Re: Win10 installation progress

2024-07-08 Thread DdC
Still struggling launching my hck app on Win10 & tomcat 9.0.88.It runs (dont laugh) on: XP/Win7 & tomcat 4.0.4 Linux-gnu & tomcat 6.0.32 Tomcat 9.0.88 displays fine with localhost:8080. App hck compiles OK (dont laugh) with a script using:CLASSPATH=.;c:\tomcat4\j2ee.jar;c:\tomcat4\webapps\hck\WEB

Re: [EXTERNAL EMAIL] Apache Tomcat Default Files - TEN-12085

2024-07-08 Thread Niranjan Rao
On 7/8/24 11:56, Pramod Kumar Adhi wrote: HI Team, We have one vulnerability related to the TEN-12085. Could you please advise on the below on how can we remediate this vulnerability. Vulnerability Description The server is not configured to return a custom page in the event of a client ZjQcmQ

Re: Apache Tomcat Default Files - TEN-12085

2024-07-08 Thread Chuck Caldarale
> On Jul 8, 2024, at 14:54, Pramod Kumar Adhi > wrote: > > We are using tomcat version 9.87 can you guide on the same. Seriously? You can’t find the 9.0.x documentation on the Tomcat web site yourself? Ok… https://tomcat.apache.org/tomcat-9.0-doc/security-howto.html - Chuck > From: Ch

RE: Apache Tomcat Default Files - TEN-12085

2024-07-08 Thread Pramod Kumar Adhi
Hi Chuck, We are using tomcat version 9.87 can you guide on the same. Thanks & Regards, Pramod Kumar Adhi From: Chuck Caldarale Sent: Tuesday, July 9, 2024 12:31 AM To: Tomcat Users List Subject: Re: Apache Tomcat Default Files - TEN-12085 [External Email] > On Jul 8, 2024, at 13:56, Pramod

Re: Apache Tomcat Default Files - TEN-12085

2024-07-08 Thread Chuck Caldarale
> On Jul 8, 2024, at 13:56, Pramod Kumar Adhi > wrote: > > We have one vulnerability related to the TEN-12085.Could you please advise on > the below on how can we remediate this vulnerability. > > Vulnerability Description > > The server is not configured to return a custom page in the eve

Apache Tomcat Default Files - TEN-12085

2024-07-08 Thread Pramod Kumar Adhi
HI Team, We have one vulnerability related to the TEN-12085.Could you please advise on the below on how can we remediate this vulnerability. Vulnerability Description The server is not configured to return a custom page in the event of a client requesting a non-existent resource. This may resu

Re: Persistent Manager Implementation Question

2024-07-08 Thread Christopher Schultz
Miguel, On 2/19/24 11:50, Miguel Vidal wrote: hey one question regarding this topic I'm facing an issue where my old app is doing a creation of multiple sessions but just one is the correct one or at least is who contains the data and works fine. the others sessions that are created contains ran

Re: Inquiry about CVE-2024-5535 Vulnerability in Tomcat 10.1.20 Version

2024-07-08 Thread Christopher Schultz
Peyton, On 7/7/24 23:50, Zhong, Peyton wrote: Because OpenSSL is one of the most widely used open-source cryptographic libraries for implementing secure communications on the internet, it is essential for us to upgrade to secure versions to mitigate various threats, especially for software su

Re: [ANN] New committer: Dimitris Soumis

2024-07-08 Thread Dimitris Soumis
Thank you very much for the warm welcome. I look forward to collaborating with all of you and continuing the great work that has made Tomcat a cornerstone project. Best regards, Dimitris On Sat, Jul 6, 2024 at 7:14 AM Igal Sapir wrote: > Congrats Dimitris! > > Welcome to the team! > > Igal > >

Re: Errors after upgrading to Tomcat 9.0.90

2024-07-08 Thread Francesco Chicchiriccò
On 2024/07/03 20:17:06 Christopher Schultz wrote: > Francesco, > > On 7/2/24 05:44, Francesco Chicchiriccò wrote: > > On 2024/06/27 14:47:48 Christopher Schultz wrote: > >> Rainer, > >> > >> On 6/21/24 07:55, Rainer Jung wrote: > >>> Am 20.06.24 um 17:52 schrieb Christopher Schultz: > Frances

[ANN] Apache Tomcat 9.0.91 available

2024-07-08 Thread Rémy Maucherat
The Apache Tomcat team announces the immediate availability of Apache Tomcat 9.0.91. Apache Tomcat 9 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 9.0.91 is a bugfix and feat

Re: Inquiry about CVE-2024-5535 Vulnerability in Tomcat 10.1.20 Version

2024-07-08 Thread Michael Osipov
On 2024/07/08 03:50:44 "Zhong, Peyton" wrote: > Hi Mark, > > Thanks for your information. Let me briefly explain for myself. > > Because OpenSSL is one of the most widely used open-source cryptographic > libraries for implementing secure communications on the internet, it is > essential for us