SAP Knowledge Base Article - Preview

3658595 - Upgrading the Tomcat server without upgrading SAP Cloud Connector.

Symptom

  1. The Tomcat server is impacted by a Common Vulnerabilities and Exposures (CVE). 
  2. The Tomcat version reached EOL.
  3. Tomcat version is very old.


Read more...

Environment

  • SAP Cloud Connector release independent 

Product

CONNECTOR FRAMEWORK all versions ; SAP Connectivity service all versions

Keywords

apache tomcat vulnerabilities, cve-2025-48989, http/2, sap cloud connector, embedded tomcat upgrade, mitigating controls, security concerns, vulnerability scan, sap development tools, latest version, Apache Tomcat, CC, SAP Cloud Connector, SCC, vulnerabilities, subset of features, SAP verification, embedded Tomcat, upgrade restrictions, modification restrictions, SAP Cloud Connector installers, configuration files, server.xml, predefined configurations, unexpected behavior, custom modifications, user risk, stability issues, support limitations, upgrade complications  , KBA , BC-MID-SCC , SAP Cloud Connector On-Demand/On-Premise Connectivity , How To

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.