What version of Apache Tomcat in Siebel Patch 2024.5, 2024.6 and 2024.7?
We are having Siebel Patch 2024.3 running in our environments. But Apache Tomcat version 9.0.85 has vulnerabilities. Also need to know how long these vulnerabilities are addressed and included in the Siebel Patch.
The Rapid7 vulnerability scans have identified the following vulnerabilities for Apache / Tomcat
* Apache Tomcat: Important: Denial of Service (CVE-2024-23672)
* Apache Tomcat: Important: Denial of Service (CVE-2024-24549)
Apache Tomcat: Important: Information Disclosure (CVE-2023-42795)
Apache Tomcat: Important: Request smuggling (CVE-2023-45648)
Apache Tomcat: Important: Request smuggling (CVE-2023-46589)
Apache Tomcat: Moderate: Open redirect (CVE-2023-41080)
Apache Tomcat: Low: Denial of Service (CVE-2023-42794)