On 05/08/2026 11:34, Roshan Patil wrote:
Dear Team,
There is no |*examples*|directory in the Apache Tomcat |webapps|
directory. I need only 10.1.58 to resolve VA. Please assist.
If there is no examples directory (which I assume means the examples web
application is not deployed), why do you need 10.1.58?
Mark
Regards,
Roshan Patil,
On 8/5/2026 12:52 PM, Döscher, Andreas (ESI) via users wrote:
Moin,
examples and documentation should always be removed in productive
environments, therefore
4. If the vulnerability only affects the *examples*web application
(specifically the WebSocket chat example), would removing the
*examples*web application be considered sufficient mitigation until
the fixed version becomes available?
is the way!
Ciao,
Andreas
PS: With documentation an attacker could be able to determine the
version of the tomcat. Please consult the security-howto.html of the
tomcat documentation.
-----Ursprüngliche Nachricht-----
Von: Roshan Patil<[email protected]>
Gesendet: Mittwoch, 5. August 2026 09:10
An:[email protected];[email protected]
Cc: Ahmad Hassan<[email protected]>
Betreff: Regarding apache-tomcat 10.1.58 version
**********************************************************************
Dear Team,
I hope you are doing well.
We are currently performing security remediation based on a
Vulnerability Assessment (VA) report.
The report indicates that our Apache Tomcat installation is
affected by *CVE-2026-66299*and recommends upgrading to *Apache Tomcat
10.1.58 or later*. The advisory states that the issue affects Apache
Tomcat versions *10.1.24 through 10.1.57*and is fixed in *10.1.58*.
However, we are unable to find Apache Tomcat *10.1.58*on the
official Apache Tomcat download page or archives.
The relevant portion of the VA report is as follows:
o *CVE:*CVE-2026-66299
o *Affected versions:*Apache Tomcat 10.1.24 through 10.1.57
o *Recommended remediation:*Upgrade to Apache Tomcat 10.1.58 or
later.
o *Additional note:*Nessus relies on the application's
self-reported version number.
Could you please help us with the following:
1. Has Apache Tomcat *10.1.58*been officially released?
2. If not, when is it expected to be available?
3. Is there an alternative fixed version that we should upgrade to in
order to remediate CVE-2026-66299?
4. If the vulnerability only affects the *examples*web application
(specifically the WebSocket chat example), would removing the
*examples*web application be considered sufficient mitigation until
the fixed version becomes available?
We appreciate your guidance, as we need to complete our organization's
security remediation and close the VA findings.
Regards,
Roshan Patil
------------------------------------------------------------------------------------------------------------
[ C-DAC is on Social-Media too. Kindly follow us at:
Facebook:https://urldefense.com/v3/__https://www.facebook.com/
CDACINDIA__;!!L8-7AA!U0klxdOOErOsRMyOyk-
cIdGn01ljqxmXVvyJmh4FurKHf_kDx-
qBpw6y4q85AE302jkPDXM4N2QePq4DdOm1S7OW$ & Twitter: @cdacindia ]
This e-mail is for the sole use of the intended recipient(s) and may
contain confidential and privileged information. If you are not the
intended recipient, please contact the sender by reply e-mail and
destroy all copies and the original message. Any unauthorized review,
use, disclosure, dissemination, forwarding, printing or copying of
this email is strictly prohibited and appropriate legal action will be
taken.
------------------------------------------------------------------------------------------------------------
This message and any attachments are intended only for the use of the
addressee and may contain information that is privileged and
confidential. If the reader of the message is not the intended
recipient or an authorized representative of the intended recipient,
you are hereby notified that any dissemination of this communication
is strictly prohibited. If you have received this communication in
error, notify the sender immediately by return email and delete the
message and any attachments from your system.
---------------------------------------------------------------------
To unsubscribe, e-mail:[email protected]
For additional commands, e-mail:[email protected]
------------------------------------------------------------------------------------------------------------
[ C-DAC is on Social-Media too. Kindly follow us at:
Facebook: https://www.facebook.com/CDACINDIA & Twitter: @cdacindia ]
This e-mail is for the sole use of the intended recipient(s) and may
contain confidential and privileged information. If you are not the
intended recipient, please contact the sender by reply e-mail and destroy
all copies and the original message. Any unauthorized review, use,
disclosure, dissemination, forwarding, printing or copying of this email
is strictly prohibited and appropriate legal action will be taken.
------------------------------------------------------------------------------------------------------------
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]