SAP Knowledge Base Article - Preview

3782507 - CVE-2026-59083 & CVE-2026-59084 Vulnerability Impact for Apache Tomcat and required configuration checks - SAP Commerce Cloud

Symptom

  • Security scanners report critical vulnerabilities in the bundled Apache Tomcat component: CVE-2026-59083 (CVSS 9.1) and CVE-2026-59084 (CVSS 9.1)
  • Findings are associated with the Tomcat runtime embedded in the platform


Read more...

Environment

SAP Commerce Cloud 2211 for JDK21

SAP Commerce Cloud 2211

Product

SAP Commerce Cloud 2211 ; SAP Commerce Cloud 2211 for JDK21

Keywords

apache tomcat, CVE-2026-59083, CVE-2026-59084, rewritevalve, encryptinterceptor, tomcat clustering, server.xml, context.xml, aes/cbc, aes/gcm, bundled tomcat, vulnerability scan, exposure assessment, configuration check, SAP commerce cloud , KBA , CEC-SCC-PLA-PL , Platform , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.