Overview
This article lists the vulnerabilities (CVEs) reported on third-party libraries and components used by 360Suite (including 360Eyes), whether 360Suite is affected, and the remediation when needed. The list is sorted from the most recent CVE to the oldest.

Legend
- Not affected: the vulnerable code or feature is not used, not reachable or not configured in the product.
- Low risk: the bundled component is in the affected range, but exploitation requires a non-default configuration or local access. It has been (or will be) upgraded anyway.
- Affected – fixed: the product shipped an affected version of the component. The fixed product version is given in the details.
- Not applicable: the component is not part of the product (for example, it belongs to a third-party platform installed on the same server).
Reported CVEs
| CVE | Component | Impact | Details & remediation |
|---|---|---|---|
| 2026 | |||
| CVE-2026-66299 | Apache Tomcat 10.1.56 | Not affected | Only affects the Tomcat examples web application, which is removed from the Tomcat bundled with 360Suite. |
| CVE-2026-59084 | Apache Tomcat 10.1.56 | Not affected | Requires the EncryptInterceptor (Tomcat clustering), which is not used by 360Suite. |
| CVE-2026-59083 | Apache Tomcat 10.1.56 | Not affected | Requires the RewriteValve, which is not enabled in the Tomcat bundled with 360Suite. |
| CVE-2026-55956 CVE-2026-55955 CVE-2026-55276 CVE-2026-53434 CVE-2026-53404 | Apache Tomcat < 10.1.56 | Affected – fixed | The bundled Tomcat was in the affected range. Fixed in 360Suite 2026.4 (Tomcat 10.1.56). |
| CVE-2026-49844 | Apache Log4j 2.25.4 | Not affected | Only affects applications using JsonTemplateLayout / MapMessage.asJson(). 360Suite does not ship the log4j-layout-template-json module. Log4j will be upgraded in an upcoming release. |
| CVE-2026-41883 | OmniFaces 4.6.5 | Not affected | Requires the CDNResourceHandler with a wildcard CDN mapping, which 360Suite does not use. Do not delete the OmniFaces jar: it is required by 360Suite. |
| CVE-2026-34500 CVE-2026-34487 CVE-2026-34483 CVE-2026-29146 CVE-2026-29145 CVE-2026-25854 CVE-2026-24880 | Apache Tomcat ≤ 10.1.52 | Affected – fixed | The bundled Tomcat was in the affected range. Fixed in 360Suite 2026.3 (Tomcat 10.1.54). |
| CVE-2026-34480 CVE-2026-34478 CVE-2026-34477 | Apache Log4j 2.25.3 | Not affected | Only concern the Socket/Syslog appenders and XML layouts, which are not used by 360Suite. Log4j upgraded to 2.25.4 in 360Suite 2026.2. |
| CVE-2026-29000 | pac4j-jwt | Not applicable | This library is not part of 360Suite or of SAP BusinessObjects. |
| CVE-2026-24734 | Apache Tomcat 10.1.48 – 10.1.50 | Low risk | Only exploitable when OCSP certificate validation is configured on a TLS connector, which is not the case in the Tomcat bundled with 360Suite. Tomcat upgraded to 10.1.52 in 360Suite 2026.2. |
| CVE-2026-24733 | Apache Tomcat 10.1.48 – 10.1.50 | Low risk | Very low impact. Tomcat upgraded to 10.1.52 in 360Suite 2026.2. |
| 2025 | |||
| CVE-2025-68161 | Apache Log4j 2.23 – 2.25.2 | Not affected | Only affects the SocketAppender, which is not used by 360Suite. Log4j upgraded to 2.25.3 in 360Suite 2026.1.1. |
| CVE-2025-66614 | Apache Tomcat 10.1.x | Not affected | Only exploitable with several virtual hosts, which are not configured in the Tomcat bundled with 360Suite. Tomcat upgraded in 360Suite 2026.2. |
| CVE-2025-66516 | Apache Tika | Not affected | 360Suite only uses Tika's detect() method to check the type of uploaded files (CSV/Excel). The vulnerable PDF parser is not used. Tika updated in 360Suite 2026.3.1. |
| CVE-2025-61795 CVE-2025-55754 CVE-2025-55752 | Apache Tomcat 10.1.46 | Low risk | Low risk in the 360Suite context. Fixed in 360Suite 2025.4.3 (Tomcat 10.1.48). |
| CVE-2025-54988 | Apache Tika | Not affected | 360Suite only uses Tika to detect file types (CSV/Excel). The vulnerable PDF (XFA) parsing is not used. Tika 3.2.2 has been bundled since 360Suite 2025.4. |
| CVE-2025-52520 CVE-2025-52434 CVE-2025-49125 CVE-2025-48988 CVE-2025-48976 | Apache Tomcat 10.1.41 | Affected – fixed | The bundled Tomcat was in the affected range. Fixed in 360Suite 2025.3.1 (Tomcat 10.1.43). |
| CVE-2025-48989 | Apache Tomcat 10.1.41 (HTTP/2) | Affected – fixed | Fixed in 360Suite 2025.4 (Tomcat 10.1.46). |
| CVE-2025-48924 | Apache Commons Lang 3 | Affected – fixed | Library updated in 360Suite 2025.4 (including 360Eyes). |
| CVE-2025-31651 CVE-2025-31650 | Apache Tomcat 10.1.39 | Affected – fixed | Fixed in hotfix 360Suite 2025.2.1 (Tomcat 10.1.41). |
| CVE-2025-24813 | Apache Tomcat | Not affected | Requires write access through the default servlet and file-based session persistence. Both are disabled in the Tomcat bundled with 360Suite, for all 360Suite versions. Tomcat was updated anyway in 360Suite 2025.2. |
| CVE-2025-1094 | PostgreSQL (psql) | Not affected | 360Suite does not use psql or the other PostgreSQL command-line tools. |
| 2024 | |||
| CVE-2024-50379 | Apache Tomcat 9.0.84 | Not affected | Requires the default servlet to be write-enabled, which is not the case in 360Suite. The bundled Tomcat was upgraded to 10.1.34 in 360Suite 2025.1. |
| CVE-2024-41730 | SAP BusinessObjects | Not applicable | Vulnerability of the SAP BusinessObjects platform. 360Suite is not concerned unless Trusted Authentication is used with 360Suite. Apply SAP's patch to your BusinessObjects platform. |
| CVE-2024-38286 | Apache Tomcat 9.0.84 | Affected – fixed | Fixed in 360Suite 2025.1 (Tomcat 10.1.34, Java 21). |
| CVE-2024-30172 CVE-2024-30171 CVE-2024-29857 | Bouncy Castle | Affected – fixed | Fixed in 360Suite 2024.2. |
| CVE-2024-29025 | Netty | Affected – fixed | Fixed in 360Suite 2024.2. |
| CVE-2024-26308 CVE-2024-25710 | Apache Commons Compress | Affected – fixed | Fixed in 360Suite 2024.2. |
| CVE-2024-24549 CVE-2024-23672 | Apache Tomcat 9.0.84 | Affected – fixed | The bundled Tomcat was in the affected range (fixed upstream in 9.0.86). Fixed in 360Suite 2025.1 (Tomcat 10.1.34). |
| CVE-2024-12801 CVE-2024-12798 | Logback (logback-core 1.3.14) | Affected – fixed | Updated to logback-core 1.5.16 in 360Suite 2025.2 (including 360Eyes). |
| CVE-2024-1597 | PostgreSQL JDBC driver | Affected – fixed | Driver upgraded in 360Suite 2024.2 (including 360Eyes). |
| 2023 | |||
| CVE-2023-50164 | Apache Struts | Not applicable | Apache Struts is not used by 360Suite. |
| CVE-2023-45648 CVE-2023-44487 CVE-2023-42794 | Apache Tomcat 9.0.80 | Not affected | The HTTP/2 connector is not configured and the Tomcat file upload component concerned is not used. Tomcat upgraded to 9.0.84 in 360Suite 2024.1. |
| CVE-2023-28708 | Apache Tomcat 9.0.71 | Not affected | Requires the RemoteIpFilter, which is not configured in 360Suite. |
| CVE-2023-5129 CVE-2023-4863 | libwebp | Not applicable | No component of 360Suite or 360Eyes uses libwebp. |
| 2022 | |||
| CVE-2022-45143 | Apache Tomcat 9.0.56 | Affected – fixed | Fixed in 360Suite 2023.1.1 (Tomcat 9.0.71). |
| CVE-2022-42889 | Apache Commons Text | Not applicable | 360Suite does not use this library. Your SAP BusinessObjects platform may be concerned: see SAP Note 2914574. |
| CVE-2022-42252 CVE-2022-34305 | Apache Tomcat | Not affected | Require a non-default configuration or the Tomcat example applications, which are not used by 360Suite. |
| CVE-2022-41203 | SAP BusinessObjects BI Platform | Not applicable | Vulnerability of the SAP BusinessObjects platform. After patching your BusinessObjects environment, we recommend updating the SAP libraries used by 360Suite. |
| CVE-2022-29885 | Apache Tomcat 9.0.56 | Not affected | Only affects clustered Tomcat installations, which is not the case of 360Suite. |
| CVE-2022-25647 | Google Gson | Affected – fixed | Transitive dependency updated in 360Suite 2025.3 (360Eyes: 2024.3). |
| CVE-2022-23302 CVE-2021-4104 CVE-2020-9488 CVE-2019-17571 | Apache Log4j 1.x | Not applicable | 360Suite uses Log4j 2. The Log4j 1.x files reported by scanners belong to the SAP BusinessObjects SDK or to other tools installed on the server. The log4j-1.2-api jar is a bridge to Log4j 2, not Log4j 1.x. |
| CVE-2022-23181 | Apache Tomcat 9.0.56 | Not affected | Only exploitable with the FileStore session persistence, which 360Suite does not use. |
| CVE-2022-22965 | Spring Framework (Spring4Shell) | Not applicable | 360Suite does not use Spring MVC / Spring WebFlux. |
| CVE-2022-3786 CVE-2022-3602 | OpenSSL | Not applicable | 360Suite does not ship OpenSSL. If OpenSSL was used to configure TLS on Tomcat, check with the team that set it up (usually your IT team). |
| CVE-2022-2625 | PostgreSQL (bundled) | Affected – fixed | New installations get PostgreSQL 12.12 from 360Suite 2022.4. For existing installations, upgrade PostgreSQL to the latest patch of the same major version (stop Tomcat and PostgreSQL, run the PostgreSQL installer, restart). |
| CVE-2022-1471 | SnakeYAML | Not affected | YAML parsing is not used by 360Suite. The library was excluded from 360Eyes in 2024.3. |
| 2021 | |||
| CVE-2021-44228 | Apache Log4j 2 (Log4Shell) | Not affected | The vulnerable JNDI lookup is not used by 360Suite (WebPlatform) or 360Eyes. Log4j was upgraded anyway to 2.16 in 2021.4.1 and to 2.17 in 2022.1.1. 360Suite Legacy (end of life since October 2021) is affected and will not be patched: migrate to 360Suite. |
| CVE-2021-25122 | Apache Tomcat 9.0.33 | Affected – fixed | Fixed in 360Suite 2022.1 (Tomcat 9.0.56). |
| 2020 | |||
| CVE-2020-9484 | Apache Tomcat | Not affected | Only exploitable with the FileStore session persistence, which 360Suite does not use. |
| 2018 | |||
| CVE-2018-1270 | Spring Framework | Not applicable | False positive: scanners confuse the LicenseSpring licensing library with the Spring Framework. |
FAQ
Can I upgrade the bundled Tomcat or Java myself?
We recommend upgrading 360Suite instead: Tomcat and Java are updated in every release and tested with the product. You can point Tomcat to a newer Java runtime of the same major version in the Java tab of the Tomcat configuration. Note that builds running on Java 8 cannot run Tomcat 10.x.
My scanner reports a jar file that 360Suite does not seem to use.
Many reported files belong to the SAP BusinessObjects SDK, to other tools installed on the same server, or to files left by a previous installation. Send us the full path of the file so we can check it.
Can I disable Tomcat?
No. 360Suite and 360Eyes run on Tomcat. You can harden it (remove the default web applications, disable the HTTP OPTIONS method).
Your CVE is not listed?
This page lists the vulnerabilities that were reported to us or analysed by our teams. It is not an exhaustive list of every CVE fixed by a component upgrade: check the Security section of the release notes for the complete list.
If your security scanner reports a CVE that is not listed here, open a ticket with the Support team and include the CVE ID, the product version, and the exact file or path flagged by the scanner. We will analyse it and add it to this page.