| Summary: Xerox evaluated DocuShare for Apache Tomcat CVE-2025-48989 and determined that standard DocuShare deployments are not affected because the vulnerable HTTP/2 condition is not present in the standard shipped configuration. The DocuShare Tomcat 9.0.120 patch upgrades the bundled Tomcat to the fixed upstream version and remains the recommended remediation for customers aligning to the supported Tomcat level. |
Overview
CVE-2025-48989 is a Tomcat issue affecting HTTP/2 connection handling. Xerox engineering assessment found that the standard DocuShare deployment does not use the vulnerable HTTP/2 path. The DocuShare Tomcat 9.0.120 patch upgrades the bundled Apache Tomcat from 9.0.106 to 9.0.120, which includes the upstream fix.
Xerox DocuShare uses a bundled Apache Tomcat installation. The Tomcat 9.0.120 patch upgrades the bundled Tomcat from 9.0.106 to 9.0.120 and includes the upstream fixes for the Tomcat advisories listed in this change set.
Resolution
- Apply the DocuShare Tomcat 9.0.120 patch for the installed DocuShare release.
- This patch upgrades the bundled Apache Tomcat to version 9.0.120.
- No application changes are required for standard DocuShare deployments.
Applies To
| DocuShare Release | Assessment |
| DocuShare 7.5 | Addressed by the Tomcat 9.0.120 patch. |
| DocuShare 7.6 | Addressed by the Tomcat 9.0.120 patch. |
| DocuShare 7.7 | Addressed by the Tomcat 9.0.120 patch. |
| DocuShare 8.0 | Addressed by the Tomcat 9.0.120 patch. |
| Important: If your environment includes custom Tomcat, connector, or TLS changes outside the standard Xerox DocuShare configuration, review those changes with Xerox DocuShare Support before applying the patch. |