Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

Cloudera 5.16.2: Tomcat upgrade

Highlighted

Cloudera 5.16.2: Tomcat upgrade

New Contributor

Hello,

 

After running a security tool on our cluster, a report found the tomcat version as outdated and vulnerable to certain threats. We have tried to find ways to upgrade Tomcat on our cluster but are not having any success with it.

 

I realize this is similar to a post https://community.cloudera.com/t5/Support-Questions/Apache-tomcat-compatibility/m-p/159988 which concerns HDP but there are no responses on that post either.

 

Does anyone have some experience with this? If so, I would be grateful for some pointers.

Thanks.

 

Regards,

CaptainJay

3 REPLIES 3
Highlighted

Re: Cloudera 5.16.2: Tomcat upgrade

Expert Contributor

Hi @CaptainJa 

 

Are you able to upgrade your environment to CDH 6? In CDH 6 Tomcat is replaced by Jetty. Please take a look at this post:

 

https://blog.cloudera.com/third-party-libraries-in-c6/

 

Regards,

Steve

Highlighted

Re: Cloudera 5.16.2: Tomcat upgrade

New Contributor

Hello @StevenOD,

 

Thanks for the reply. We have considered this but at the moment, the client requirements limits our usage to 5.16.x

Re: Cloudera 5.16.2: Tomcat upgrade

Expert Contributor

@CaptainJa  The version of Tomcat used in CDH 5.16.2 should not have any vulnerabilities. Could you share the CVE that is reported CDH is vulnerable to?

 

Per the notice [1] independent upgrade of Tomcat is not supported and we are moving towards newer versions in CDH6 => Cloudera Enterprise 6 has replaced Tomcat 6 with Jetty 9 and is not susceptible to Tomcat security issues.

 

LINKS: [1] https://community.cloudera.com/t5/Customer/CDH-5-support-for-Tomcat-6/ta-p/73655

Don't have an account?
Coming from Hortonworks? Activate your account here