Customers utilizing the Automation Analytics and Intelligence (AAI) IWSz Connector frequently encounter strict security compliance requirements that necessitate rapid patching of third-party components like Apache Tomcat. In current deployments, such as AAI 24.4, Apache Tomcat is bundled within the IWSz Connector runtime. This coupling means that Tomcat security vulnerabilities (CVEs) can only be remediated during official AAI release cycles. For organizations with monthly or quarterly remediation SLAs, waiting for the next product release may not be sustainable.
Product limitation: DE208778
roadcom Product Management has reviewed and accepted the request to support customer-managed or externalized Tomcat instances for the AAI IWSz Connector. This enhancement allows users to patch Tomcat independently of the AAI release cycle, ensuring continuous compliance with security.