Tomcat Vulnerabilities - Impact with Clarity
search cancel

Tomcat Vulnerabilities - Impact with Clarity

book

Article ID: 405556

calendar_today

Updated On:

Products

Clarity FedRAMP Clarity PPM On Premise Clarity PPM SaaS

Issue/Introduction

In the latest scan below vulnerabilities were reported with Clarity?  

Environment

Clarity 16.3.x, 16.4.1, 16.4.2,16.4.3

Resolution

All the above mentioned vulnerabities are not conclusive and NVD assessment not yet provided.  

  • CVE-2025-48976 - Clarity uses apache.commons.fileupload. In Clarity Version 16.4.2/16.4.3 - The version is 1.6.0 and Clarity is not impacted.
  • CVE-2025-49125 - Clarity support tomcat 9.0.98 with 16.3.2 . Upgrade to 9.0.106 should be ok as  higher patch level are supported 
  • CVE-2025-49124 -  Clarity support tomcat 9.0.98 with 16.3.2 . Upgrade to 9.0.106 should be ok as  higher patch level are supported 
  • CVE-2025-48988 - Clarity support tomcat 9.0.98 with 16.3.2 . Upgrade to 9.0.106 should be ok as  higher patch level are supported

However Tomcat can still be upgraded to the mitigated version of Tomcat mentioned in above CVE's 

  • Steps to upgrade Tomcat with Clarity 
    • Stop and remove all the clarity services 
    • Download the Tomcat from Apache  Website
    • Extract the downloaded Tomcat to the servers 
    • Edit the properties.xml and update the path of the new tomcat version
    • Re deploy the services and test in around use cases 

Note: If there are certificates installed please cross check and update the same to ensure its working