Vulnerability Remediation for Bundled Apache Tomcat in AAI IWSz Connector
search cancel

Vulnerability Remediation for Bundled Apache Tomcat in AAI IWSz Connector

book

Article ID: 450644

calendar_today

Updated On:

Products

Automation Analytics & Intelligence

Issue/Introduction

This article addresses inquiries regarding vulnerability scans reporting issues in the Apache Tomcat instance bundled with the AAI IWSz Connector.

Please find the CVE ID's reported for vulnerabilities.

CVE-2026-24734
CVE-2026-29145
CVE-2026-24880
CVE-2026-29146
CVE-2026-34500
CVE-2026-34483
CVE-2026-34487
CVE-2026-25854
CVE-2026-32990
CVE-2026-43514
CVE-2026-41284
CVE-2026-43513
CVE-2026-42498
CVE-2026-43515
CVE-2026-43512
CVE-2026-41293
CVE-2025-55752
CVE-2025-61795
CVE-2026-24733
CVE-2025-66614

Environment

  • Product: Automation Analytics & Intelligence(AAI) version 24.x
  • Component: IWSz Connector

Cause

The Apache Tomcat instance is bundled within the AAI IWSz Connector to ensure compatibility. Because it is a bundled component, it cannot be patched independently of the connector release cycle to maintain support and functionality.

Resolution

The fix for the vulnerabilties will tentatively be included in AAI version 26.0.0 though there's no ETA yet.