Retail Point-of-Service Solutions (MOSC)

MOSC Banner

Xoffice 21.0.3 – Tomcat Upgrade Beyond 9.0.84

Oracle documentation for Xoffice 21.0.3 lists support for Tomcat 9.0.84. We’re exploring whether it would be acceptable to upgrade to a newer Tomcat 9.0.x, specifically 9.0.105, to ensure we’re covered against the latest security patches and CVEs.

From Tomcat’s own release notes, versions beyond 9.0.84 (including 9.0.105) address several important issues such as:

  • CVE-2024-50379 – Possible information disclosure in WebSocket frame handling.
  • CVE-2024-23672 – Fix for potential request smuggling when using HTTP/2 with specific connectors.

Additional stability fixes in TLS/ALPN negotiation and async request handling.

Given these security improvements, we’d like to ask:

  • Is there any restriction in Xoffice 21.0.3 that would prevent us from upgrading to Tomcat 9.0.105 or newer in the same 9.0.x line?

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center