问题描述
Does the COMSOL software contain the Apache Tomcat® software and, if so, is it affected by known security vulnerabilities in it? Can the bundled Apache Tomcat version be updated before the next COMSOL product update?
解决方法
Summary
The following COMSOL functionality uses a bundled distribution of the Apache Tomcat 9 software:
- The documentation and help in COMSOL Multiphysics and COMSOL Documentation (when the Help > Source > Location preference is set to Local)
- Running COMSOL Multiphysics in client-server mode
- Model Manager server
- COMSOL Server
Install the latest product updates for the COMSOL software to also update its bundled Apache Tomcat distribution. If needed, see below for more information about Apache Tomcat security vulnerabilities, the Apache Tomcat version bundled with each supported COMSOL version, and how to manually update the bundled Apache Tomcat distribution.
Security vulnerabilities
All security vulnerabilities that are fixed in released versions of Apache Tomcat 9 are listed by the Apache Tomcat security team on the Apache Tomcat 9.x vulnerabilities page.
Not all security vulnerabilities of Apache Tomcat apply to the COMSOL software, since the COMSOL software does not use all functionality of its bundled Apache Tomcat distribution and may not have enabled the affected features. In fact, COMSOL software typically only uses a relatively limited subset of the Apache Tomcat functionality.
Vulnerability assessments
The following vulnerabilities, associated with an important severity score, are fixed in the latest version of Apache Tomcat but not in the version of Apache Tomcat that is bundled with the latest supported COMSOL versions:
CVE-2026-65637
Assessment: Not affected
In the default configuration, COMSOL software does not allow configuring client certificate requirements or binding other security settings to the TLS virtual host names. So even if HTTP/2 with multiple TLS hosts were configured (in principle possible with Model Manager server) then any bypass of SNI validation has no security implication for the server.CVE-2026-29146, CVE-2026-34486
Assessment: Not affected
This vulnerability affects Tomcat'sEncryptInterceptor, which is used to encrypt communication between nodes in a Tomcat cluster. COMSOL software does not use Tomcat clustering or theEncryptInterceptor.CVE-2026-65182
Assessment: Not affected
This vulnerability requires overlapping Tomcat security constraints for URL paths, where a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. COMSOL software does not use this type of Tomcat security constraint configuration.CVE-2026-65927
Assessment: Not affected
This vulnerability affects the[N]flag in Tomcat'sRewriteValveand can result in incorrect processing of rewrite rules that are used for access control. COMSOL software does not use TomcatRewriteValverules for access control and does not configure the affected[N]functionality.CVE-2026-68569
Assessment: Not affected
This vulnerability affects authentication against a TomcatDataSourceRealmin combination with authentication mechanisms such asCLIENT-CERTorSPNEGO. COMSOL software does not use a TomcatDataSourceRealmfor authentication.CVE-2026-68763
Assessment: Affected
This vulnerability is a denial-of-service vulnerability in Tomcat's HTTP/2 implementation and requires HTTP/2 to be enabled, which is only possible for Model Manager server. If a Model Manager server is exposed to untrusted networks, a manual update to Apache Tomcat 9.0.121 is recommended. Alternatively, HTTP/2 can be disabled in Model Manager server and provided through a reverse proxy server if needed.
Updating Apache Tomcat
Installing the latest product updates for the COMSOL software ensures that the bundled Apache Tomcat software is kept at the latest released version that has been fully tested together with the COMSOL software.
In some situations you might want to update to the most recently released Apache Tomcat version, either before a product update has been released for the COMSOL software with an updated Apache Tomcat software or for a version of COMSOL that no longer receives updates.
Note: Compatibility between the COMSOL software and new versions of Apache Tomcat cannot be guaranteed until the new version has been tested. Any known incompatible versions may be listed in this Knowledge Base article in the future. If you manually update the bundled Apache Tomcat software in a COMSOL installation and encounter issues, please check back here or contact COMSOL Support.
The following explains how you can manually update the bundled Apache Tomcat software for a COMSOL software installation:
- Go to the Tomcat 9 Software Downloads page.
- Download the Binary Distributions > Core > zip archive to a temporary location and unzip it.
- Locate the Apache Tomcat subdirectory of the COMSOL software installation to target. The following are the default installation folders:
- On Windows systems:
C:\Program Files\COMSOL\COMSOL63\[Product]\bin\tomcat - On macOS systems:
/Applications/COMSOL63/[Product]/bin/tomcat - On Linux systems:
/usr/local/comsol63/[product]/bin/tomcat - The
[Product]path segment isMultiphysicsfor COMSOL Multiphysics,Serverfor COMSOL Server, andModelManagerServerfor COMSOL Model Manager Server.
- On Windows systems:
- Stop any COMSOL software currently running from the targeted installation.
- Copy the
libandbindirectories from the extracted Apache Tomcat software to the Apache Tomcat subdirectory of the targeted COMSOL software installation, overwriting the existing files in these folders. The steps to copy a folder and merge its contents with the destination are different for each operating system:- On Windows: Drag the
libandbinfolders from the extracted Apache Tomcat software to thebin\tomcatfolder of the targeted COMSOL software installation. You should get a confirmation dialog saying that the destination has files with the same names. Choose to Replace the files in the destination. - On macOS: Copy all the contents of the
libandbindirectories from the extracted Apache Tomcat software to the respective directories inbin/tomcatfolder of the targeted COMSOL software installation, overwriting the existing files in these folders. - On Linux: Change to the extracted Apache Tomcat software directory in a terminal window and use the command
cp -r lib bin [path-to-comsol]/bin/tomcat, where[path-to-comsol]is the path of the targeted COMSOL software installation.
- On Windows: Drag the
- The remaining Tomcat directories and COMSOL-provided configuration files should be left as-is.
- Restart the COMSOL software from the targeted installation directory and verify that it works as before.
You will typically need administrator privileges to modify the COMSOL software installation, for example by giving administrative credentials on Windows systems or performing the operation as root with sudo on Linux systems.
If you want to restore the original version of the bundled Apache Tomcat software in the COMSOL software installation, use the Setup launcher from the installation to run the COMSOL installer and use the Add/Remove Products and Reinstall option to restore the installation to its original state.
Apache Tomcat version
The following versions of the Apache Tomcat software are included with the currently supported versions of COMSOL:
- COMSOL 6.4 Update 3:
Apache Tomcat 9.0.118 - COMSOL 6.3 Update 3:
Apache Tomcat 9.0.115
In general, the version of the Apache Tomcat software included with a particular COMSOL software installation can be determined by the following steps:
- Locate the Apache Tomcat directory of the COMSOL software installation, as explained in the previous section.
- Open the
catalina.jararchive from itslibdirectory using a tool like 7-Zip. - View the
META-INF/MANIFEST.MFfile in a text editor. - Read the Apache Tomcat version from the
Implementation-Versionentry.
COMSOL 已尽一切合理的努力核实本页面所提供的信息。但请注意,所有资源与文档仅供学习参考。COMSOL 不对其有效性作任何明示或暗示的声明,亦不承担因所披露数据的准确性而产生的任何法律责任。本文提及的所有商标均为其各自所有者的财产。有关完整的商标信息,请参阅相关产品手册。
