Genesys Engage on-premises

 View Only

Discussion Thread View
  • 1.  Tomcat Vulnerability - CVE-2025-24813

    Posted 03-20-2025 15:03

    Good day everyone,

    Checking in to see if anyone has proceeded to upgrade and validate their Tomcat installation to the latest release addressing this vulnerability?

    [SECURITY] CVE-2025-24813 Potential RCE and/or information disclosure and/or information corruption with partial PUT-Apache Mail Archives

    We have used 9.0.58 and are looking to upgrade to 9.0.99.  I'm looking to see if I can anything from Genesys to acknowledge or address this.

    Kind Regards,

    Mike.


    #RoutingandOrchestration(ACD/IVR)
    #SecurityandCompliance

    ------------------------------
    Michael Silverman
    VP Operations
    ------------------------------


  • 2.  RE: Tomcat Vulnerability - CVE-2025-24813

    Posted 03-21-2025 05:29

    I'm not sure what all components you're running on Tomcat.

    But we're running Apache Tomcat/9.0.100 for GRAT, GRE, and Composer without any issues.



    ------------------------------
    Tony Morrow
    Sr. Genesys Engineer
    ------------------------------



  • 3.  RE: Tomcat Vulnerability - CVE-2025-24813

    Posted 03-21-2025 08:06

    We've been having to upgrade all of our Tomcat's every time there's a critical & high CVE. With the exception of GCXI, we're in the process of upgrading everything from 9.0.98 to 9.0.102. Like Tony, GRAT, GRE, Routing/Composer Web, and other non-Engage apps.



    ------------------------------
    Karl Theurer
    NA
    ------------------------------



  • 4.  RE: Tomcat Vulnerability - CVE-2025-24813

    Posted 03-21-2025 13:01

    Thank you Tony and Karl for the fast responses, for this environment, it is primarily for Routing application services.

    Regards,

    Mike.



    ------------------------------
    Michael Silverman
    VP Operations
    ------------------------------



  • 5.  RE: Tomcat Vulnerability - CVE-2025-24813

    Posted 04-25-2025 19:20

    Hello Karl, when you did your apache upgrade, did you have to pay any particular attention to the GART or GRE components? are there any folders or files you needed to copy to the new Tomcat folder? I am planning to upgrade iWD from Apache Tomcat 9.0.5 to 9.0.99. Thanks.



    ------------------------------
    Wilfried Mayala
    Genesys Consultant
    ------------------------------



  • 6.  RE: Tomcat Vulnerability - CVE-2025-24813

    Posted 04-29-2025 17:16

    On our end there was nothing really out of the ordinary for either GRAT or GRE. We do have GRE & GRAT co-located on one of the nodes, so it's what we would expect, port adjustments and GRAT needing the SQL driver.



    ------------------------------
    Karl Theurer
    NA
    ------------------------------



  • 7.  RE: Tomcat Vulnerability - CVE-2025-24813

    Posted 04-30-2025 01:15

    Hello Karl,

    Thank you very much for the follow up. I will go ahead with my upgrade and revert back if I come across anything.



    ------------------------------
    Wilfried Mayala
    Genesys Consultant
    ------------------------------



Need Help finding something?

Check out the Genesys Knowledge Network - your all-in-one access point for Genesys resources