On AutoSys 24.1/WCC 24.1 servers, the following CVEs are showing up in the vulnerabilities report:
PATH INSTALLED_VERSION REQUIRED_VERSION
-------- ------------------------------- -------------------------------
xxx/xx/xxxxx/webserver. 11.0.10 11.0.11
CVE-2025-55752
CVE-2025-61795
AutoSys 24.1
WCC 24.1
The CVE-2025-55752 vulnerability is addressed beginning with the Tomcat 11.0.11 version
The CVE-2025-61795 vulnerability is addressed beginning with the Tomcat 11.0.12 version
To address these vulnerabilities, Client can download the Tomcat 11.0.12 version of Tomcat from that Apache Tomcat download site, or they can upgrade to AutoSys 24.1SP1/WCC 24.1SP1 that comes bundled with Tomcat 11.0.13