Service Catalog 12.9.02 vulnerability - Apache Tomcat

Document ID : KB000098049
Last Modified Date : 25/05/2018
Show Technical Document Details
Question:
There are vulnerabilities associated with the version of Apache Tomcat which ships with Service Catalog 12.9. Can we upgrade Tomcat, what version can we upgrade to and how do we perform the upgrade?
Answer:
The version of Apache Tomcat used by Service Catalog 12.9 can safely be upgraded to version 7.0.82. Steps to do this are as follows:

1) Download Apache-Tomcat-7.0.82:
apache-tomcat-7.0.82-windows-x86.zip for 32 bit
apache-tomcat-7.0.82-windows-x64.zip for 64 bit

2) Stop the catalog service

3) Upgrade Tomcat using ant upgrade-tomcat command from the CA Service Catalog command prompt.

C:\Program Files\CA\Service Catalog>ant upgrade-tomcat
Buildfile: build.xml
_start-maintenance-log:
[mkdir] Created dir: C:\Program Files\CA\Service Catalog\conf-backup\20180302-0528
[echo] Maintenance started: Friday March 02, 2018 05:28:04 AM EST by Administrator
_services-warning:
[echo] Please shutdown all related services before continuing
[input] Press Return key to continue...
upgrade-tomcat:
[input] Location of new tomcat zip:
C:\apache-tomcat-7.0.82.zip
[input] What is the version of the new Apache Tomcat (e.g. 6.0.38):
7.0.82
[input] Are you sure you want to upgrade tomcat to 7.0.82? (y, n)
y
[unzip] Expanding: C:\apache-tomcat-7.0.82.zip into C:\Users\ADMINI~1\AppData\Local\Temp\2\tomca
t-7.0.82
[mkdir] Created dir: C:\Program Files\CA\Service Catalog\embedded\tomcat-20180302-0528
[echo] Copying the current tomcat to C:\Program Files\CA\Service Catalog/embedded/tomcat-201803
02-0528
[copy] Copying 653 files to C:\Program Files\CA\Service Catalog\embedded\tomcat-20180302-0528
[copy] Copied 113 empty directories to 2 empty directories under C:\Program Files\CA\Service Ca
talog\embedded\tomcat-20180302-0528
[echo] Copied the current tomcat to C:\Program Files\CA\Service Catalog/embedded/tomcat-2018030
2-0528
[copy] Copying 633 files to C:\Program Files\CA\Service Catalog\embedded\tomcat
[echo] Apache Tomcat 7.0.82 has been successfully installed.
BUILD SUCCESSFUL
Total time: 13 minutes 9 seconds

Once this is complete, restart the Service Catalog service and the upgrade to the new version of Tomcat will be complete.