|
|
Geronimo 2.1.x and Geronimo 2.2 Patch Instructions the Tomcat CVE-2010-2227 Vulnerability.The Tomcat project has recently discovered a security vulnerability which may allow a remote denial of service attack or an information vulnerability exploit. For more information on this security vulnerability kindly refer the following document: How is Apache Geronimo Affected?Apache Geronimo uses the Tomcat component as one of the supported web containers for the Geronimo server. Servers configured with to use the Tomcat web container may be vulnerable to either of these exploits. These issues have been fixed in the tomcat-parent-6.0.29 component used by Geronimo. How can I avoid these vulnerabilities in Apache Geronimo?If you wish to remain on an existing version of Geronimo, the installation can be patched to avoid the vulnerability. The following steps will upgrade the Tomcat libraries used by the server.
|
|
|
Apache Geronimo, Geronimo, Apache, the Apache feather, and the Apache Geronimo project logo are trademarks of the Apache Software Foundation. | Privacy Policy - Copyright © 2003-2011, The Apache Software Foundation, Licensed under ASL 2.0. |