Critical Vulnerability in Siebel IP 25.1 catalina.jar file
We have recently upgraded our siebel systems from IP13 to IP 25.1 in both dev & Prod systems.
Recently our Security Team has flagged a critical vulnerability in catalina.jar file of app_external(AI) and suggesting us to upgrade Tomcat version to recent version.
Since this vulnerability is fixed in IP 25.9 we tried to upgrade only AI Server with 25.9 version on our Dev Environment instead of doing a full Siebel Upgrade from 25.1 to 25.9
We don't see any issues so far and are able to access Siebel Dev Application post the upgrade of only AI Server to 25.9 without any issues with SES Server on 25.1