Skip to main content
Joe Rybacek
Inspiring
August 10, 2016
Answered

Does Adobe have a timeline for providing a hotfix for TomCat 7.0.70

  • August 10, 2016
  • 1 reply
  • 1989 views

I know I've asked these questions before, but I'm curious if anyone can speak to when Tomcat bundled with ColdFusion 11 will be updated?

Tomcat is bundled as part of ColdFusion 11, previously Adobe has provided a hotfix to upgrade Tomcat.  Is this something on the product road map?

Tomcat 7.0.70 fixes the following issue:

    This topic has been closed for replies.
    Correct answer Anit_Kumar

    Hi Joe,

    CF is not impacted with CVE-2016-3092 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3092

    Regards,

    Anit Kumar

    1 reply

    Anit_Kumar
    Community Manager
    Anit_KumarCommunity ManagerCorrect answer
    Community Manager
    August 12, 2016

    Hi Joe,

    CF is not impacted with CVE-2016-3092 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3092

    Regards,

    Anit Kumar

    pete_freitag
    Participating Frequently
    August 12, 2016

    Thanks for providing that info Anit! I have downgraded this from Important to Warning on the HackMyCF scanner. I still keep it as Warning because I think it is important to know incase your CFML code makes use of the vulnerable classes.

    I still hope Adobe plans to upgrade to Tomcat 7.0.70+ in CF10/11, and 8.0.36+ in CF2016 in the next update. It is important for many organizations.

    Anit_Kumar
    Community Manager
    Community Manager
    August 16, 2016

    That will definitely happen Pete.

    Regards,

    Anit Kumar