A security may flag CVE CVE-2026-6629 for SiteMinder Access Gateway and Agent for Sharepoint Servers. This is a vulnerability published for Tomcat 9.0.120 and older.
SiteMinder Access Gateway r12.8.7 and higher bundles Apache Tomcat 9.0.x as the application server. Tomcat versions vary by the Access Gateway release:
r12.8.7: Apache Tomcat 9.0.65
r12.8.8: Apache Tomcat 9.0.83
r12.8.8.1 Apache Tomcat 9.0.86
r12.9 ships with Apache Tomcat 9.0.100.0
KB281190 (archived) delivered Tomcat 9.0.86
KB381451 (archived) delivered Tomcat 9.0.96
KB383137 (archived) delivered Tomcat 9.0.97
KB384944 (archived) delivered Tomcat 9.0.98
KB397315 (archived) delivered Tomcat 9.0.104
KB403333 (archived) delivered Tomcat 9.0.106
KB406223 (archived) delivered Tomcat 9.1.107
KB417926 (archived) delivered Tomcat 9.0.110
KB431996 (archived) delivered Tomcat 9.0.115
KB437528 (archived) delivered Tomcat 9.0.117
KB441198 (archived) delivered Tomcat 9.0.118
KB448422 (archived) delivered Tomcat 9.0.120
The SiteMinder Web Agent for Sharepoint 12.8.7 and higher bundles Tomcat 9.0.x as the application server. Tomcat versions vary by the Web Agent for Sharepoint release:
r12.8.7: Tomcat 9.0.70
r12.8.8: Tomcat 9.0.83
KB406223 (archived) delivered Tomcat 9.0.105
KB417957 (archived) delivered Tomcat 9.0.107
KB417957 (archived) delivered Tomcat 9.0.111
KB433468 (archived) delivered Tomcat 9.0.115
KB437759 (archived) delivered Tomcat 9.1.117
KB442459 (archived) delivered Tomcat 9.1.118
KB448541 (archived) delivered Tomcat 9.1.120
PRODUCT: SiteMinder
COMPONENT: Access Gateway Server
VERSIONS: 12.8.x; 12.9
OS: Any
COMPONENT: Sharepoint Agent
VERSIONS: 12.8.x
OS: Any
CVE-2026-66299: DoS in WebSocket chat example
SEVERITY: Low
DESCRIPTION: The WebSocket chat example provided an unbounded buffer for undelivered messages. A maliciously slow client could cause the buffer to grow continuously, eventually leading to an memory exhaustion and failure of the Tomcat process.
IMPACTS: Tomcat 9.0.89 to 9.0.120
REMEDIATED: Tomcat 9.0.121
NOTE: Users who followed the security guidance to remove the examples web application are not affected.
CVE-2026-66299 does not impact any versions of SiteMinder Access Gateway or the Agent for Sharepoint.
The security notification for CVE-2026-66299 indicates that this vulnerability can be mitigated by doing the following:
Delete any of the following:
<Tomcat_Install_Dir>/webapps/examples/
<Tomcat_Install_Dir>/webapps/examples.war
<Tomcat_Install_Dir>/work/Catalina/localhost/examples/
While SiteMinder bundles an instance of the Apache Tomcat app server with Access Gateway and the Agent for Sharepoint, this is not a full installation. SiteMinder does not include the 'examples' web application with its installation. Therefore the Tomcat instance on SiteMinder components is not susceptible to this vulnerability.