Is Applications Manager or its integrated webserver vulnerable to CVE-2025-55752, CVE-2025-55754, and/or CVE-2025-61795?
Applications Manager 9.6+
CVE-2025-55752: Applications Manager is not vulnerable. The necessary condition is Rewrite Valve required. We don't provide any such option to enable Tomcat's Rewrite valve.
CVE-2025-55754: Applications Manager is not vulnerable. The necessary condition is that embedded Tomcat should run in an interactive console. We write log to the file.
CVE-2025-61795: Applications Manager is not vulnerable. The necessary condition is to perform multipart upload, which is not supported by the web server.