Applications Manager and Tomcat vulnerability CVE-2025-46701
search cancel

Applications Manager and Tomcat vulnerability CVE-2025-46701

book

Article ID: 411418

calendar_today

Updated On:

Products

CA Automic Applications Manager (AM)

Issue/Introduction

Is Applications Manager affected by Tomcat vulnerability CVE-2025-46701?

Environment

Applications Manager 9.4 and above

Resolution

While you can still upgrade Tomcat to the latest version on 9.4.x and 9.5.x, CGI servlet is disabled by default in Tomcat application which we used to ship in 9.4.x and 9.5.x, hence it is not vulnerable

If needed, refer to Upgrading or updating Tomcat.

For version 9.6's integrated webserver, Applications Manager is using Tomcat core library which is unaffected.