<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How is Apache Tomcat CVE-2025-24813 addressed by SAS? in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/964413#M29867</link>
    <description>&lt;P&gt;Since the parameter is not modified and it already has the default value of "true" you don't have to change anything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Apr 2025 12:31:17 GMT</pubDate>
    <dc:creator>ghassanzghaib</dc:creator>
    <dc:date>2025-04-16T12:31:17Z</dc:date>
    <item>
      <title>How is Apache Tomcat CVE-2025-24813 addressed by SAS?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/963159#M29812</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the recent&amp;nbsp;Apache Tomcat vulnerability "CVE-2025-24813" addressed by SAS?&lt;/P&gt;&lt;P&gt;I didn't find anything related to this vulnerability in the SAS Security Bulletins.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 20:24:42 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/963159#M29812</guid>
      <dc:creator>ghassanzghaib</dc:creator>
      <dc:date>2025-04-01T20:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: How is Apache Tomcat CVE-2025-24813 addressed by SAS?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/963188#M29814</link>
      <description>&lt;P&gt;Since this is a question directly to the vendor, I suggest that you open a track to tech support or contact your accont responsible. &lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 06:22:45 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/963188#M29814</guid>
      <dc:creator>LinusH</dc:creator>
      <dc:date>2025-04-02T06:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: How is Apache Tomcat CVE-2025-24813 addressed by SAS?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/963205#M29816</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apparently the installation is vulnerable only if the "readonly" parameter in the Tomcat's "web.xml" is changed to "false" from it's default value of "true".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is our Tomcat susceptible to CVE-2025-24813?&lt;/P&gt;&lt;P&gt;&amp;nbsp;Solution Verified&amp;nbsp;- Updated&amp;nbsp;March 21 2025 at 3:15 PM&amp;nbsp;-&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://can01.safelinks.protection.outlook.com/?url=https%3A%2F%2Faccess.redhat.com%2Fsolutions%2F7112382&amp;amp;data=05%7C02%7CMarie-Anne.Ellyton%40videotron.com%7C43a8a732524045ccff5a08dd7158aad2%7C4fc2565872c242bf913ccb9ae315a689%7C0%7C0%7C638791347825278550%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=iS30FKvN%2FcqddzUuyecFw6Zbx%2FSkB0cwR2H5x5zsaTQ%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;English&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Environment&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;JBoss Web Server&lt;UL&gt;&lt;LI&gt;5.x&lt;/LI&gt;&lt;LI&gt;6.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Red Hat Enterprise Linux&lt;UL&gt;&lt;LI&gt;8.x&lt;/LI&gt;&lt;LI&gt;9.x&lt;/LI&gt;&lt;LI&gt;10.x&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Red Hat Satellite&lt;/LI&gt;&lt;LI&gt;Red Hat Identity Management&lt;/LI&gt;&lt;LI&gt;Tomcat&lt;UL&gt;&lt;LI&gt;9.0.x&lt;/LI&gt;&lt;LI&gt;10.1.x&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Issue&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Security reports are raising concerns about&amp;nbsp;&lt;A href="https://can01.safelinks.protection.outlook.com/?url=https%3A%2F%2Faccess.redhat.com%2Fsecurity%2Fcve%2Fcve-2025-24813&amp;amp;data=05%7C02%7CMarie-Anne.Ellyton%40videotron.com%7C43a8a732524045ccff5a08dd7158aad2%7C4fc2565872c242bf913ccb9ae315a689%7C0%7C0%7C638791347825318927%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=LxBzcHDZHa5f2vkR%2BBU0RlWJPHn7ARn0uyyfO4tDQdY%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;CVE-2025-24813&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;for our Tomcat version and requesting we upgrade.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Are we truly susceptible?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Resolution&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;The impact of this vulnerability is heavily limited to non-default configurations that are not typically used.&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;If the readonly flag of the DefaultServlet on theweb.xml&amp;nbsp;is not changed to false (its default of true is safe), then there is no impact&lt;/STRONG&gt;. That would have to be added in a block like below of the tomcat or a webapp's&amp;nbsp;web.xml:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;A href="https://can01.safelinks.protection.outlook.com/?url=https%3A%2F%2Faccess.redhat.com%2Fsolutions%2F7112382&amp;amp;data=05%7C02%7CMarie-Anne.Ellyton%40videotron.com%7C43a8a732524045ccff5a08dd7158aad2%7C4fc2565872c242bf913ccb9ae315a689%7C0%7C0%7C638791347825343130%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=kwGRRW4U4GXlTJaEZxBMiHRfPq3QM%2BFy2eG8vrKNoxw%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Raw&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;servlet&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;servlet-name&amp;gt;default&amp;lt;/servlet-name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;servlet-class&amp;gt;org.apache.catalina.servlets.DefaultServlet&amp;lt;/servlet-class&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;init-param&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;param-name&amp;gt;debug&amp;lt;/param-name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;param-value&amp;gt;0&amp;lt;/param-value&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/init-param&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;init-param&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;param-name&amp;gt;listings&amp;lt;/param-name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;param-value&amp;gt;false&amp;lt;/param-value&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/init-param&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;init-param&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;param-name&amp;gt;readonly&amp;lt;/param-name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;param-value&amp;gt;false&amp;lt;/param-value&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/init-param&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;load-on-startup&amp;gt;1&amp;lt;/load-on-startup&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;/servlet&amp;gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If installed from a RHEL tomcat package, you could use a simple check like below to see if there is any line added to change the parameter at all:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;A href="https://can01.safelinks.protection.outlook.com/?url=https%3A%2F%2Faccess.redhat.com%2Fsolutions%2F7112382&amp;amp;data=05%7C02%7CMarie-Anne.Ellyton%40videotron.com%7C43a8a732524045ccff5a08dd7158aad2%7C4fc2565872c242bf913ccb9ae315a689%7C0%7C0%7C638791347825362802%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=JGX0Qic8muUS3gDVBe%2FtWvMchezvcb6eIdcnvnUxL%2Fg%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Raw&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;$ grep readonly /etc/tomcat/web.xml | grep -v "&amp;lt;\!--"&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Or if a JWS zip install:&lt;BR /&gt;line added to change the parameter at all:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;A href="https://can01.safelinks.protection.outlook.com/?url=https%3A%2F%2Faccess.redhat.com%2Fsolutions%2F7112382&amp;amp;data=05%7C02%7CMarie-Anne.Ellyton%40videotron.com%7C43a8a732524045ccff5a08dd7158aad2%7C4fc2565872c242bf913ccb9ae315a689%7C0%7C0%7C638791347825380194%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=PwKB9T3xd74hjb9jg2XDON9PuJeqf7Tb0MvuUleXuSQ%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Raw&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;$ grep readonly /path/to/JWS_HOME/tomcat/conf/web.xml | grep -v "&amp;lt;\!--"&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;You may also check any deployed custom apps and their&amp;nbsp;WEB-INF/web.xml&amp;nbsp;for any modifications of their own:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;A href="https://can01.safelinks.protection.outlook.com/?url=https%3A%2F%2Faccess.redhat.com%2Fsolutions%2F7112382&amp;amp;data=05%7C02%7CMarie-Anne.Ellyton%40videotron.com%7C43a8a732524045ccff5a08dd7158aad2%7C4fc2565872c242bf913ccb9ae315a689%7C0%7C0%7C638791347825397959%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=jx%2FBNkOb%2ByxksnfB2EqaTO9MFy5Dpcl3fCe4iZUQ6nA%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Raw&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;$ grep readonly /path/to/webappname/WEB-INF/web.xml | grep -v "&amp;lt;\!--"&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 14:15:59 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/963205#M29816</guid>
      <dc:creator>ghassanzghaib</dc:creator>
      <dc:date>2025-04-02T14:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: How is Apache Tomcat CVE-2025-24813 addressed by SAS?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/964222#M29857</link>
      <description>quick verification ... this is the block that should be changed:&lt;BR /&gt;    &amp;lt;servlet&amp;gt;&lt;BR /&gt;        &amp;lt;servlet-name&amp;gt;default&amp;lt;/servlet-name&amp;gt;&lt;BR /&gt;        &amp;lt;servlet-class&amp;gt;org.apache.catalina.servlets.DefaultServlet&amp;lt;/servlet-class&amp;gt;&lt;BR /&gt;        &amp;lt;init-param&amp;gt;&lt;BR /&gt;            &amp;lt;param-name&amp;gt;debug&amp;lt;/param-name&amp;gt;&lt;BR /&gt;            &amp;lt;param-value&amp;gt;0&amp;lt;/param-value&amp;gt;&lt;BR /&gt;        &amp;lt;/init-param&amp;gt;&lt;BR /&gt;        &amp;lt;init-param&amp;gt;&lt;BR /&gt;            &amp;lt;param-name&amp;gt;listings&amp;lt;/param-name&amp;gt;&lt;BR /&gt;            &amp;lt;param-value&amp;gt;false&amp;lt;/param-value&amp;gt;&lt;BR /&gt;        &amp;lt;/init-param&amp;gt;&lt;BR /&gt;        &amp;lt;load-on-startup&amp;gt;1&amp;lt;/load-on-startup&amp;gt;&lt;BR /&gt;    &amp;lt;/servlet&amp;gt;&lt;BR /&gt;And as it is now our web server IS vulnerable. Is this to be changed on all web.xml files?&lt;BR /&gt;</description>
      <pubDate>Mon, 14 Apr 2025 14:52:03 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/964222#M29857</guid>
      <dc:creator>DJWanna</dc:creator>
      <dc:date>2025-04-14T14:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: How is Apache Tomcat CVE-2025-24813 addressed by SAS?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/964223#M29858</link>
      <description>Sorry, follow-up question ... would we need to do a rebuild/redeploy of all the web applications? I see that web.xml is in all of the apps.</description>
      <pubDate>Mon, 14 Apr 2025 15:15:44 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/964223#M29858</guid>
      <dc:creator>DJWanna</dc:creator>
      <dc:date>2025-04-14T15:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: How is Apache Tomcat CVE-2025-24813 addressed by SAS?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/964411#M29866</link>
      <description>&lt;P&gt;Your block is missing the 'readonly' parameter but if you look at the comments somewhere above in the file you'll find the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;!-- readonly Is this context "read only", so HTTP --&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;!-- commands like PUT and DELETE are --&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;!-- rejected? [true] --&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[true]&lt;/STRONG&gt; is the default value so you should be ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You only need to change the file in:&amp;nbsp; \SASConfig\Lev1\Web\WebAppServer\SASServer1_1\conf&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 12:27:19 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/964411#M29866</guid>
      <dc:creator>ghassanzghaib</dc:creator>
      <dc:date>2025-04-16T12:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: How is Apache Tomcat CVE-2025-24813 addressed by SAS?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/964413#M29867</link>
      <description>&lt;P&gt;Since the parameter is not modified and it already has the default value of "true" you don't have to change anything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 12:31:17 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/964413#M29867</guid>
      <dc:creator>ghassanzghaib</dc:creator>
      <dc:date>2025-04-16T12:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: How is Apache Tomcat CVE-2025-24813 addressed by SAS?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/964590#M29880</link>
      <description>&lt;P&gt;As already mentioned earlier, please report this to SAS Support and further assistance can then be provided. Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 13:55:22 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/How-is-Apache-Tomcat-CVE-2025-24813-addressed-by-SAS/m-p/964590#M29880</guid>
      <dc:creator>UtkarshGupta</dc:creator>
      <dc:date>2025-04-18T13:55:22Z</dc:date>
    </item>
  </channel>
</rss>

