Hi Sebastian, Thank you for the clarification.
I came across these mitigation details in the vendor advisories referenced by the CVE entries linked from the Tomcat Security 9 page. For each of the 12 vulnerabilities, the referenced Tomcat advisory includes the same mitigation guidance: Users of the affected versions should apply one of the following mitigations: - *Remove the examples web application* - Upgrade to Apache Tomcat 11.0.26 - Upgrade to Apache Tomcat 10.1.60 - Upgrade to Apache Tomcat 9.0.122 The advisories referenced from CVE.org are: - https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp - https://lists.apache.org/thread/mss45z99lcdd5dtpgcn45dy82f3toswc - https://lists.apache.org/thread/tyqcqk99g7ghgk22641vf67vghcyswnw - https://lists.apache.org/thread/mb1pjjooqytrl6hbvbt3rw1lqwlon4cz - https://lists.apache.org/thread/nmkmjp9l53y8h3oc4n8fc0bkw9dv15sk - https://lists.apache.org/thread/bzwps6ck4szf2hmksbbon3syyl9qnkv8 - https://lists.apache.org/thread/r0dj3h1pbn4wv96fhsfrnz3t6874t6do - https://lists.apache.org/thread/ypvlkjqsq0480fnk9jm6h9qllddwlw4w - https://lists.apache.org/thread/qkmsos3s8chn5053qr466rzwv6sk5gjg - https://lists.apache.org/thread/y5r9fvjo7ol24mkoyoc0st8bqrfyqcyn - https://lists.apache.org/thread/bl5b6rxqh3vb2k9bj2794vhor7o6xl3z - https://lists.apache.org/thread/njjcdkkzqyzx4n3ffc4ffjmyh5mpl1gr To clarify, we do not deploy the examples application in our production environments. My question was primarily to understand whether the presence of the examples application is actually a prerequisite for exploiting these vulnerabilities. When reviewing some of the associated fixes, I noticed changes in Tomcat core classes rather than in the examples application itself. That is what led me to wonder whether "Remove the examples web application" is a valid mitigation for these CVEs, or whether upgrading to the fixed Tomcat release is ultimately the only effective mitigation. In other words, if the examples application is not deployed, should these vulnerabilities still be considered applicable to the Tomcat instance, thereby requiring an upgrade to 9.0.122? Thank you again for your time and clarification. Kind regards, Thiru On Sat, Sep 26, 2026 at 1:48 PM Sebastian Trost via users < [email protected]> wrote: > On 9/26/26 04:27, Thiru wrote: > > The security page lists 12 issues (4 Important, 3 Moderate, and 5 Low > > severity). For each of these CVEs, the mitigation appears to be: > > > > Remove the examples web application > > > > [...] > > > > Could you please clarify whether all 12 CVEs are only exploitable through > > the *examples* web application, and whether removing the examples > > application alone is sufficient to mitigate these vulnerabilities without > > upgrading Tomcat? > > > > Reference: > > https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.122 > Where do you see this? The only reference to removing the examples web > application I can find is in the CVE disclosure mails from Mark. The > "Remove the examples web application" started with his mail on July > 28th, CVE-2026-66299, and continues in every other CVE disclosure. My > guess is that he simply forgot to remove the "Remove the examples web > application" again and this is a copy&paste mistake. > > Why are people so hung up about this examples web application? It always > has been best practice to remove it and the other web applications in > production environments and to only deploy your own web app. > > Sebastian > > > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > >
