<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PEN test reveals out of date Apache Tomcat on Extreme Control in ExtremeControl</title>
    <link>https://community.extremenetworks.com/t5/extremecontrol/pen-test-reveals-out-of-date-apache-tomcat-on-extreme-control/m-p/100847#M483</link>
    <description>&lt;P&gt;Hi Stefan,&lt;/P&gt;&lt;P&gt;Extreme Control&amp;nbsp;&lt;SPAN&gt;23.11.12.3.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I will have to ask customer for the Tomcat version.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Edit: 9.0.84 is part of 23.11.12.3.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Rob&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jul 2024 15:30:06 GMT</pubDate>
    <dc:creator>RobertD1</dc:creator>
    <dc:date>2024-07-05T15:30:06Z</dc:date>
    <item>
      <title>PEN test reveals out of date Apache Tomcat on Extreme Control</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/pen-test-reveals-out-of-date-apache-tomcat-on-extreme-control/m-p/100839#M480</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;What would our response be to a customer that runs a PEN test and has identified the version of Apache Tomcat to be old (not the latest)? Understand that products have to be updated when new updates are made, just don't know whether Apache Tomcat will be updated in-line with times it gets updated. Not seeing the change&amp;nbsp; in the release notes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think known vulnerabilities are checked against XIQ-SE and NAC and software changes that protect against an issue would be planned for a future release, this would make sense. Unclear if this should be in the release notes or not?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seeking advice on this valid security concern and what to say to the end customer.&lt;/P&gt;&lt;P&gt;I can ask for versions of Apache Tomcat on their installed version but just posting to learn more about how to respond to this type of concern.&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 09:27:55 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/pen-test-reveals-out-of-date-apache-tomcat-on-extreme-control/m-p/100839#M480</guid>
      <dc:creator>RobertD1</dc:creator>
      <dc:date>2024-07-05T09:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: PEN test reveals out of date Apache Tomcat on Extreme Control</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/pen-test-reveals-out-of-date-apache-tomcat-on-extreme-control/m-p/100840#M481</link>
      <description>&lt;P&gt;Knowing the exact installed version of Tomcat would indeed be helpful. Security-Fixes are also patched into older releases afaik.&lt;/P&gt;&lt;P&gt;Updates of such components/packages don't make it to the release notes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What version of ExtremeControl is in use?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 09:54:38 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/pen-test-reveals-out-of-date-apache-tomcat-on-extreme-control/m-p/100840#M481</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2024-07-05T09:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: PEN test reveals out of date Apache Tomcat on Extreme Control</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/pen-test-reveals-out-of-date-apache-tomcat-on-extreme-control/m-p/100845#M482</link>
      <description>&lt;P&gt;Please see&amp;nbsp;&lt;A href="https://extreme-networks.my.site.com/ExtrArticleDetail?an=000107545" target="_blank"&gt;https://extreme-networks.my.site.com/ExtrArticleDetail?an=000107545&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;In general Extreme provides monthly security vulnerability remediation releases. If your customer is concerned about pen-test results they should upgrade to the latest OS release (24.2.15 at this point) on all supported products (XIQ-SE, Control, Analytics) and re-scan.&lt;/P&gt;&lt;P&gt;If this is a scan on XMC, Control, Analytics 8.5.x then no updates will be provided and the software is AS IS prior to end of life September 2024.&lt;/P&gt;&lt;P&gt;You should also search our SA articles as a number of them have been published over time with various Apache related vulnerabilities and we are either not vulnerable (by design) or we've since upgraded the Apache Tomcat engine.&lt;/P&gt;&lt;P&gt;I believe as of 24.2.15 the Apache TC version is 9.0.87.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 12:43:19 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/pen-test-reveals-out-of-date-apache-tomcat-on-extreme-control/m-p/100845#M482</guid>
      <dc:creator>Robert_Haynes</dc:creator>
      <dc:date>2024-07-05T12:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: PEN test reveals out of date Apache Tomcat on Extreme Control</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/pen-test-reveals-out-of-date-apache-tomcat-on-extreme-control/m-p/100847#M483</link>
      <description>&lt;P&gt;Hi Stefan,&lt;/P&gt;&lt;P&gt;Extreme Control&amp;nbsp;&lt;SPAN&gt;23.11.12.3.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I will have to ask customer for the Tomcat version.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Edit: 9.0.84 is part of 23.11.12.3.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Rob&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 15:30:06 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/pen-test-reveals-out-of-date-apache-tomcat-on-extreme-control/m-p/100847#M483</guid>
      <dc:creator>RobertD1</dc:creator>
      <dc:date>2024-07-05T15:30:06Z</dc:date>
    </item>
  </channel>
</rss>

