Impact of Apache Tomcat related vulnerabilities on Endpoint Protection Manager
search cancel

Impact of Apache Tomcat related vulnerabilities on Endpoint Protection Manager

book

Article ID: 280961

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

You want to know the impact of following Apache Tomcat related vulnerabilities on Symantec Endpoint Protection Manager (SEPM):

  • CVE-2024-23672
  • CVE-2024-24549
  • CVE-2026-43513
  • CVE-2026-41284
  • CVE-2026-41293
  • CVE-2026-43514
  • CVE-2026-42498
  • CVE-2026-53404 
  • CVE-2026-53434
  • CVE-2026-55276
  • CVE-2026-59084
  • CVE-2026-59083
  • CVE-2026-66299
  • CVE-2026-53404
  • CVE-2026-50229
  • CVE-2026-55957
  • CVE-2026-55956
  • CVE-2026-55955
  • CVE-2026-55276
  • CVE-2026-53434

Environment

SEPM 14.3 RU9/10, 14.4

Resolution

  • CVE-2024-23672/CVE-2024-24549: No Impact, SEPM is not vulnerable.

  • CVE-2026-43513/CVE-2026-41284/CVE-2026-41293/CVE-2026-43514/CVE-2026-42498: No impact
    Although the SEPM uses the impacted version (Apache Tomcat 9.0.98), it does not use the affected functionality.

  • CVE-2026-53404: No impact

  • CVE-2026-53434: No impact

  • CVE-2026-55276: No impact

  • CVE-2026-59084: No impact
    SEPM does not use the affected configuration

  • CVE-2026-59083: No impact
    SEPM does not use the affected configuration

  • CVE-2026-66299: No impact
    SEPM deploys Tomcat without its example applications. RU9 Tomcat version 9.0.83 is also below the affected range (9.0.89–9.0.120).

  • CVE-2026-53404: No impact
    SEPMs don't define OR condition in Tomcat rewrite.config (in sepm\tomcat\instances\sepm-api\conf\Catalina_WS).

  • CVE-2026-50229: No impact
    SEPM doesn't contain the "examples" folder in the Tomcat installation.

  • CVE-2026-55957: No impact
    JNDIRealm component is not used in SEPM.

  • CVE-2026-55956: No impact
    SEPM's security rules use a different configuration pattern than the one required to trigger this issue.

  • CVE-2026-55955: No impact
    SEPM does not use Tomcat's built-in clustering or replication features, so the mechanism this issue depends on is never active in the product.

  • CVE-2026-55276: No impact
    SEPM doesn't define logEffectiveWebXml to log the effective web.xml.

  • CVE-2026-53434: No impact
    SEPM Tomcat only uses the Java embedded in the SEPM installation.