Skip to main content
Question

CVE on Tomcat 9.0.0-9.0.9 and 8.5.5-8.5.31, ie Jamf Pro 10.6

  • July 27, 2018
  • 17 replies
  • 88 views

Forum|alt.badge.img+5

Just had my security guys pick me up about the Tomcat released with 10.6 thats currnetly on our pre box. dont like the idea of updating tomcat outside Jamf so reached out to our account manager to see if at least Jamf is aware.

http://mail-archives.us.apache.org/mod_mbox/www-announce/201807.mbox/%3C20180722090623.GA92700@minotaur.apache.org%3E

17 replies

bpavlov
Forum|alt.badge.img+18
  • Esteemed Contributor
  • July 27, 2018

And what did Jamf say?


Forum|alt.badge.img+18
  • Honored Contributor
  • July 27, 2018

Posting so i get notified of new posts too ;)


Forum|alt.badge.img+9
  • Valued Contributor
  • July 27, 2018

have a feeling we may see a Jamf Pro 10.6.1 with updated tomcat


stephanpeterson
Forum|alt.badge.img+12

following....


donmontalvo
Forum|alt.badge.img+36
  • Hall of Fame
  • July 30, 2018

Following...


Forum|alt.badge.img+8
  • Contributor
  • July 31, 2018

Joining the conga line


Forum|alt.badge.img+18
  • Honored Contributor
  • July 31, 2018

Oof I have the upgrade scheduled for this weekend. I reached out to Jamf for comment.


Forum|alt.badge.img+11
  • Valued Contributor
  • August 1, 2018

Following...


Forum|alt.badge.img+7
  • Contributor
  • August 1, 2018

Interested


Forum|alt.badge.img+18
  • Honored Contributor
  • August 1, 2018

Jamf suggested using the root.war manual upgrade path to me. This would be upgrading without upgrading Tomcat itself.

EDIT - Spoke with Jamf again and they don't want us changing our upgrade method from the Windows .msi based one. To be continued another weekend.


Forum|alt.badge.img+7
  • Valued Contributor
  • August 7, 2018

So is Apache Tomcat 8.5.31 not updatable without breaking JAMF? Because 8.5.32 is current including REQUIRED patching from 8.5.31.


bpavlov
Forum|alt.badge.img+18
  • Esteemed Contributor
  • August 7, 2018

@ryan.yohnk I don't know if you're the right person to tag on this, but you had responded to my discussion on Java support moving forward.

I was wondering whether you or someone else on Jamf could comment on the current situation with the Tomcat CVEs being discussed here.


Forum|alt.badge.img+18
  • Honored Contributor
  • August 7, 2018

We are in a hold pattern on Jamf upgrades until the CVE(s) are closed out. Interested to know where we are in closing these out.


Forum|alt.badge.img+7
  • Employee
  • August 7, 2018

Jamf is planning a release associated with this vulnerability based on the severity. I cannot share a timeline yet on when, but it is in process.


Forum|alt.badge.img+14
  • Honored Contributor
  • August 27, 2018

Pro Tip: Instead of posting a one-word comment to the thread to be informed of future updates, 'Add Bookmark'.

:)


Forum|alt.badge.img+18
  • Honored Contributor
  • August 27, 2018

But i like adding to my count of new notifications.


Forum|alt.badge.img+7
  • Employee
  • August 27, 2018

P.S. We released 10.6.2 on August 21 to address this CVE. You can find 10.6.2 in Jamf Nation in your assets. What's New in 10.6.2