Skip to main content
Joe Rybacek
Inspiring
August 11, 2015
Answered

When will Adobe provide a hotfix for TomCat 7.0.54

  • August 11, 2015
  • 1 reply
  • 2188 views

I can upgrade Tomcat myself, but that approach isn't documented and isn't likely to be supported by Adobe.


Tomcat is bundled as part of ColdFusion 11, so I would hope Adobe would either provide a hotfix or suggest a supported method to upgrade Tomcat.


Tomcat 7.0.59 fixes the following issues:

  • Security Manager bypass CVE-2014-7810
  • Request Smuggling issue CVE-2014-0227
  • Denial of Service issue CVE-2014-0230
This topic has been closed for replies.
Correct answer Anit_Kumar

I understand Joe. But as mentioned earlier, it will be in the next CF update. It's too early, to specify an exact date as of now.

Regards,

Anit Kumar


Hi Joe,

Tomcat is now upgraded to 7.0.64. The update is available in pre-release as of now and would be live soon. Please refer to the following blog articles.

http://blogs.coldfusion.com/post.cfm/coldfusion-11-update-7-is-available-for-early-access

ColdFusion 10 Update 18 is available for early access — Adobe ColdFusion Blog

Regards,

Anit Kumar

1 reply

Anit_Kumar
Inspiring
August 11, 2015

I am looking into this Joe.

Regards,

Anit Kumar

Joe Rybacek
Inspiring
August 17, 2015

Hi Anit.  Any updates or thoughts on those security issues?

Joe Rybacek
Inspiring
September 25, 2015

It will be probably be in the next CF update.

Regards,

Anit Kumar


Next CF update meaning CF12 or CF11 hotfix 7?