360Suite - Third-party vulnerabilities (CVE) status

360Suite - Third-party vulnerabilities (CVE) status

Overview

This article lists the vulnerabilities (CVEs) reported on third-party libraries and components used by 360Suite (including 360Eyes), whether 360Suite is affected, and the remediation when needed. The list is sorted from the most recent CVE to the oldest.

Info
In most cases, the remediation is to upgrade to the latest 360Suite version: the bundled Apache Tomcat, Java and libraries are updated in every release. Only supported 360Suite versions are analysed.

Legend

  • Not affected: the vulnerable code or feature is not used, not reachable or not configured in the product.
  • Low risk: the bundled component is in the affected range, but exploitation requires a non-default configuration or local access. It has been (or will be) upgraded anyway.
  • Affected – fixed: the product shipped an affected version of the component. The fixed product version is given in the details.
  • Not applicable: the component is not part of the product (for example, it belongs to a third-party platform installed on the same server).

Reported CVEs

CVEComponentImpactDetails & remediation
2026
CVE-2026-66299Apache Tomcat 10.1.56Not affectedOnly affects the Tomcat examples web application, which is removed from the Tomcat bundled with 360Suite.
CVE-2026-59084Apache Tomcat 10.1.56Not affectedRequires the EncryptInterceptor (Tomcat clustering), which is not used by 360Suite.
CVE-2026-59083Apache Tomcat 10.1.56Not affectedRequires the RewriteValve, which is not enabled in the Tomcat bundled with 360Suite.
CVE-2026-55956
CVE-2026-55955
CVE-2026-55276
CVE-2026-53434
CVE-2026-53404
Apache Tomcat < 10.1.56Affected – fixedThe bundled Tomcat was in the affected range. Fixed in 360Suite 2026.4 (Tomcat 10.1.56).
CVE-2026-49844Apache Log4j 2.25.4Not affectedOnly affects applications using JsonTemplateLayout / MapMessage.asJson(). 360Suite does not ship the log4j-layout-template-json module. Log4j will be upgraded in an upcoming release.
CVE-2026-41883OmniFaces 4.6.5Not affectedRequires the CDNResourceHandler with a wildcard CDN mapping, which 360Suite does not use. Do not delete the OmniFaces jar: it is required by 360Suite.
CVE-2026-34500
CVE-2026-34487
CVE-2026-34483
CVE-2026-29146
CVE-2026-29145
CVE-2026-25854
CVE-2026-24880
Apache Tomcat ≤ 10.1.52Affected – fixedThe bundled Tomcat was in the affected range. Fixed in 360Suite 2026.3 (Tomcat 10.1.54).
CVE-2026-34480
CVE-2026-34478
CVE-2026-34477
Apache Log4j 2.25.3Not affectedOnly concern the Socket/Syslog appenders and XML layouts, which are not used by 360Suite. Log4j upgraded to 2.25.4 in 360Suite 2026.2.
CVE-2026-29000pac4j-jwtNot applicableThis library is not part of 360Suite or of SAP BusinessObjects.
CVE-2026-24734Apache Tomcat 10.1.48 – 10.1.50Low riskOnly exploitable when OCSP certificate validation is configured on a TLS connector, which is not the case in the Tomcat bundled with 360Suite. Tomcat upgraded to 10.1.52 in 360Suite 2026.2.
CVE-2026-24733Apache Tomcat 10.1.48 – 10.1.50Low riskVery low impact. Tomcat upgraded to 10.1.52 in 360Suite 2026.2.
2025
CVE-2025-68161Apache Log4j 2.23 – 2.25.2Not affectedOnly affects the SocketAppender, which is not used by 360Suite. Log4j upgraded to 2.25.3 in 360Suite 2026.1.1.
CVE-2025-66614Apache Tomcat 10.1.xNot affectedOnly exploitable with several virtual hosts, which are not configured in the Tomcat bundled with 360Suite. Tomcat upgraded in 360Suite 2026.2.
CVE-2025-66516Apache TikaNot affected360Suite only uses Tika's detect() method to check the type of uploaded files (CSV/Excel). The vulnerable PDF parser is not used. Tika updated in 360Suite 2026.3.1.
CVE-2025-61795
CVE-2025-55754
CVE-2025-55752
Apache Tomcat 10.1.46Low riskLow risk in the 360Suite context. Fixed in 360Suite 2025.4.3 (Tomcat 10.1.48).
CVE-2025-54988Apache TikaNot affected360Suite only uses Tika to detect file types (CSV/Excel). The vulnerable PDF (XFA) parsing is not used. Tika 3.2.2 has been bundled since 360Suite 2025.4.
CVE-2025-52520
CVE-2025-52434
CVE-2025-49125
CVE-2025-48988
CVE-2025-48976
Apache Tomcat 10.1.41Affected – fixedThe bundled Tomcat was in the affected range. Fixed in 360Suite 2025.3.1 (Tomcat 10.1.43).
CVE-2025-48989Apache Tomcat 10.1.41 (HTTP/2)Affected – fixedFixed in 360Suite 2025.4 (Tomcat 10.1.46).
CVE-2025-48924Apache Commons Lang 3Affected – fixedLibrary updated in 360Suite 2025.4 (including 360Eyes).
CVE-2025-31651
CVE-2025-31650
Apache Tomcat 10.1.39Affected – fixedFixed in hotfix 360Suite 2025.2.1 (Tomcat 10.1.41).
CVE-2025-24813Apache TomcatNot affectedRequires write access through the default servlet and file-based session persistence. Both are disabled in the Tomcat bundled with 360Suite, for all 360Suite versions. Tomcat was updated anyway in 360Suite 2025.2.
CVE-2025-1094PostgreSQL (psql)Not affected360Suite does not use psql or the other PostgreSQL command-line tools.
2024
CVE-2024-50379Apache Tomcat 9.0.84Not affectedRequires the default servlet to be write-enabled, which is not the case in 360Suite. The bundled Tomcat was upgraded to 10.1.34 in 360Suite 2025.1.
CVE-2024-41730SAP BusinessObjectsNot applicableVulnerability of the SAP BusinessObjects platform. 360Suite is not concerned unless Trusted Authentication is used with 360Suite. Apply SAP's patch to your BusinessObjects platform.
CVE-2024-38286Apache Tomcat 9.0.84Affected – fixedFixed in 360Suite 2025.1 (Tomcat 10.1.34, Java 21).
CVE-2024-30172
CVE-2024-30171
CVE-2024-29857
Bouncy CastleAffected – fixedFixed in 360Suite 2024.2.
CVE-2024-29025NettyAffected – fixedFixed in 360Suite 2024.2.
CVE-2024-26308
CVE-2024-25710
Apache Commons CompressAffected – fixedFixed in 360Suite 2024.2.
CVE-2024-24549
CVE-2024-23672
Apache Tomcat 9.0.84Affected – fixedThe bundled Tomcat was in the affected range (fixed upstream in 9.0.86). Fixed in 360Suite 2025.1 (Tomcat 10.1.34).
CVE-2024-12801
CVE-2024-12798
Logback (logback-core 1.3.14)Affected – fixedUpdated to logback-core 1.5.16 in 360Suite 2025.2 (including 360Eyes).
CVE-2024-1597PostgreSQL JDBC driverAffected – fixedDriver upgraded in 360Suite 2024.2 (including 360Eyes).
2023
CVE-2023-50164Apache StrutsNot applicableApache Struts is not used by 360Suite.
CVE-2023-45648
CVE-2023-44487
CVE-2023-42794
Apache Tomcat 9.0.80Not affectedThe HTTP/2 connector is not configured and the Tomcat file upload component concerned is not used. Tomcat upgraded to 9.0.84 in 360Suite 2024.1.
CVE-2023-28708Apache Tomcat 9.0.71Not affectedRequires the RemoteIpFilter, which is not configured in 360Suite.
CVE-2023-5129
CVE-2023-4863
libwebpNot applicableNo component of 360Suite or 360Eyes uses libwebp.
2022
CVE-2022-45143Apache Tomcat 9.0.56Affected – fixedFixed in 360Suite 2023.1.1 (Tomcat 9.0.71).
CVE-2022-42889Apache Commons TextNot applicable360Suite does not use this library. Your SAP BusinessObjects platform may be concerned: see SAP Note 2914574.
CVE-2022-42252
CVE-2022-34305
Apache TomcatNot affectedRequire a non-default configuration or the Tomcat example applications, which are not used by 360Suite.
CVE-2022-41203SAP BusinessObjects BI PlatformNot applicableVulnerability of the SAP BusinessObjects platform. After patching your BusinessObjects environment, we recommend updating the SAP libraries used by 360Suite.
CVE-2022-29885Apache Tomcat 9.0.56Not affectedOnly affects clustered Tomcat installations, which is not the case of 360Suite.
CVE-2022-25647Google GsonAffected – fixedTransitive dependency updated in 360Suite 2025.3 (360Eyes: 2024.3).
CVE-2022-23302
CVE-2021-4104
CVE-2020-9488
CVE-2019-17571
Apache Log4j 1.xNot applicable360Suite uses Log4j 2. The Log4j 1.x files reported by scanners belong to the SAP BusinessObjects SDK or to other tools installed on the server. The log4j-1.2-api jar is a bridge to Log4j 2, not Log4j 1.x.
CVE-2022-23181Apache Tomcat 9.0.56Not affectedOnly exploitable with the FileStore session persistence, which 360Suite does not use.
CVE-2022-22965Spring Framework (Spring4Shell)Not applicable360Suite does not use Spring MVC / Spring WebFlux.
CVE-2022-3786
CVE-2022-3602
OpenSSLNot applicable360Suite does not ship OpenSSL. If OpenSSL was used to configure TLS on Tomcat, check with the team that set it up (usually your IT team).
CVE-2022-2625PostgreSQL (bundled)Affected – fixedNew installations get PostgreSQL 12.12 from 360Suite 2022.4. For existing installations, upgrade PostgreSQL to the latest patch of the same major version (stop Tomcat and PostgreSQL, run the PostgreSQL installer, restart).
CVE-2022-1471SnakeYAMLNot affectedYAML parsing is not used by 360Suite. The library was excluded from 360Eyes in 2024.3.
2021
CVE-2021-44228Apache Log4j 2 (Log4Shell)Not affectedThe vulnerable JNDI lookup is not used by 360Suite (WebPlatform) or 360Eyes. Log4j was upgraded anyway to 2.16 in 2021.4.1 and to 2.17 in 2022.1.1. 360Suite Legacy (end of life since October 2021) is affected and will not be patched: migrate to 360Suite.
CVE-2021-25122Apache Tomcat 9.0.33Affected – fixedFixed in 360Suite 2022.1 (Tomcat 9.0.56).
2020
CVE-2020-9484Apache TomcatNot affectedOnly exploitable with the FileStore session persistence, which 360Suite does not use.
2018
CVE-2018-1270Spring FrameworkNot applicableFalse positive: scanners confuse the LicenseSpring licensing library with the Spring Framework.

FAQ

Can I upgrade the bundled Tomcat or Java myself?

We recommend upgrading 360Suite instead: Tomcat and Java are updated in every release and tested with the product. You can point Tomcat to a newer Java runtime of the same major version in the Java tab of the Tomcat configuration. Note that builds running on Java 8 cannot run Tomcat 10.x.

My scanner reports a jar file that 360Suite does not seem to use.

Many reported files belong to the SAP BusinessObjects SDK, to other tools installed on the same server, or to files left by a previous installation. Send us the full path of the file so we can check it.

Can I disable Tomcat?

No. 360Suite and 360Eyes run on Tomcat. You can harden it (remove the default web applications, disable the HTTP OPTIONS method).

Your CVE is not listed?

This page lists the vulnerabilities that were reported to us or analysed by our teams. It is not an exhaustive list of every CVE fixed by a component upgrade: check the Security section of the release notes for the complete list.

If your security scanner reports a CVE that is not listed here, open a ticket with the Support team and include the CVE ID, the product version, and the exact file or path flagged by the scanner. We will analyse it and add it to this page.