Blackduck scans of the EM have revealed vulnerabilities in two open source components:
Scanned EM version:
10.8
.
1.6
CVE-2022-40151 (score 6.7, medium)
CVE-2022-41966 (score 6.7, medium)
Apache Tomcat 8.5.83 à fix in 8.5.84
CVE-2022-45143 (score 4.6, medium)
(file locations:
javax.servlet_3.1.0.jar -> apache-jsp-8.5.70-tc81.jar -> /org/apache/juli/logging/
org.mortbay.jetty_9.4.49.jar -> apache-jsp-8.5.70-tc81.jar -> /org/apache/juli/logging/
Release : 10.8
Related to defect # DE556350
To be fixed in 10.8 SP1