Re: Tomcat FREAK Issue

2016-07-17 Thread uzair rashid
Hello Christopher, Did you or anyone have a gauge on how we might fix this? Thank you! On Thu, Jul 14, 2016 at 8:04 PM, uzair rashid <uzairrashi...@gmail.com> wrote: > Hello Chris, > > We are using Tomcat version: 6.0.36.0 > > JRE 1.6.0 > > Do you think I

Re: Tomcat FREAK Issue

2016-07-14 Thread uzair rashid
net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Uzair, > > On 7/14/16 10:12 AM, uzair rashid wrote: > > Running Tomcat 6.x > > Which one exactly? > > > and every week during vulnerability scans we are having the > > following results

Re: SSL/TLS and ciphers vulnerability

2016-07-14 Thread uzair rashid
Jeffrey, Working for a corporation that has strict ssl and security requirements.. There is no way to use the tools you suggested, since the tomcat URLs are not exposed. On Thu, Jul 14, 2016 at 8:41 AM, Jeffrey Janner wrote: > Hi folks, > > I've been off the list

Tomcat FREAK Issue

2016-07-14 Thread uzair rashid
Hello Experts: Running Tomcat 6.x and every week during vulnerability scans we are having the following results: Vulnerability References: SSL/TLS Server Factoring RSA Export Keys (FREAK) vulnerability Impact: Exploitation allows an attacker to bypass security restrictions on the

clustered environment

2016-02-29 Thread uzair rashid
Hello Experts Background,: windows boxes, cms servers, bobj, tomcat servers 7.057. Distributed landscape. (Clustered) Ive configured the server xml for clustering and distributable to true in the web xml. In the cms, we have a Java null pointer exception. At login it first says page is

Tomcat 5.0.xx migration

2016-02-09 Thread uzair rashid
Hello Experts: Most of our business is running Tomcat 7.x.xx or later. But, we have a business function of ours that is using Tomcat 5.0.xx. Unfortunately, this is causing a lot of issues in terms of vulnerability remediation. Apache Tomcat Servlet Host Manager Servlet Cross-Site Scripting

SSL FREAK vulnerability issue

2015-08-10 Thread uzair rashid
I am having an issue with tomcat version: Apache Tomcat 7.0.57 . Windows Server 2008 R2 Enterprise. I am using mssql and BOBJ as well. The issue is our servers are noticing a FREAK vulnerability issue during scan.. Could someone please help me address how to fix FREAK vulnerability in Tomcat. I

Re: Parse and SSL issue

2015-07-19 Thread uzair rashid
) at javax.naming.spi.NamingManager.getObjectInstance(NamingManager.java:304) On Sat, Jul 18, 2015 at 1:34 AM, Konstantin Kolinko knst.koli...@gmail.com wrote: .2015-07-17 21:19 GMT+03:00 uzair rashid uzairrashi...@gmail.com: Hello: I am having an issue with tomcat version: Apache Tomcat 7.0.57 . Windows Server

Re: Please help

2015-07-17 Thread uzair rashid
) at java.lang.reflect.Method.invoke(Method.java:597) I missed that point of the error as well! Could you please give your input On Thu, Jul 16, 2015 at 8:25 PM, Caldarale, Charles R chuck.caldar...@unisys.com wrote: From: uzair rashid [mailto:uzairrashi...@gmail.com] Subject: Please help Please

Please help

2015-07-16 Thread uzair rashid
) at org.apache.catalina.util.LifecycleBase.start(LifecycleBase.java:150) at org.apache.catalina.core.ContainerBase.startInternal(ContainerBase.java:1109) Can you please guide me in the right direction Regards Uzair Rashid