ConnectAll Apache Tomcat 9.0 Remote Code Execution - Vulnerability (CVE-2025-24813) mitigation
search cancel

ConnectAll Apache Tomcat 9.0 Remote Code Execution - Vulnerability (CVE-2025-24813) mitigation

book

Article ID: 399629

calendar_today

Updated On:

Products

ConnectAll On-Prem

Issue/Introduction

We have received vulnerability for Apache Tomcat on the Connectall server.

vulnerability - Apache Tomcat 9.0 Remote Code Execution - Vulnerability (CVE-2025-24813)

The remediation they have provided is to upgrade Tomcat.

Customers are advised to upgrade Apache Tomcat to the new 9.0.99 version to remediate this vulnerability.

Resolution

It will be necessary to upgrade to our ConnectAll 3.8.0.2 version.  I recommend upgrading directly to our 3.8.0.2 version, as it includes a couple of important fixes.  You can find the downloads here:  

https://support.broadcom.com/group/ecx/productfiles?sellable=VSMINS990&release=3.1.0&os=MULTI-PLATFORM&servicePk=0&language=EN