Guiseppe,
Throwing in my 2cts. I assume noone here could improve the situation. The rating is already low. So unless your company weighs the rating of the app higher than the NIST rating, this cannot be solved. I don't know who is forcing you to update - in my company we could always get approval of a risk acceptance with a comprehensible explanation. On a different note, I don't see a reason why you should not be able to update a minor version. You would have to update anyways if the CVSS would be a "real" 9.1... Peter > Am 21.07.2026 um 20:12 schrieb Sebastian Trost via users > <[email protected]>: > > Giuseppe, > >> On 7/21/26 18:51, LAURIA Giuseppe via users wrote: >> And I assume that this will not get any better in the future, but that such >> cases are still often discovered which do not concern us. >> Couldn’t there be something better from the Tomcat corner? > Since this is an open source project I'm sure that suggestions are always > welcome. > > Sebastian > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
