| Summary: Xerox evaluated DocuShare for Apache Tomcat CVE-2026-43515 and determined that standard DocuShare deployments are not affected because the vulnerable method-security condition is not present in the standard shipped configuration. The DocuShare Tomcat 9.0.120 patch upgrades the bundled Tomcat to the fixed upstream version and is the recommended remediation for customers aligning to the supported Tomcat release. |
Overview
CVE-2026-43515 is a moderate Tomcat security constraints issue affecting specific HTTP method handling. The standard DocuShare deployment does not expose the vulnerable condition. The DocuShare Tomcat 9.0.120 patch upgrades the bundled Tomcat to the fixed version.
Xerox DocuShare uses a bundled Apache Tomcat installation. The Tomcat 9.0.120 patch upgrades the bundled Tomcat from 9.0.106 to 9.0.120 and includes the upstream fixes for the Tomcat advisories listed in this change set.
Resolution
- Apply the DocuShare Tomcat 9.0.120 patch for the installed DocuShare release.
- This patch upgrades the bundled Apache Tomcat to version 9.0.120.
- No application changes are required for standard DocuShare deployments.
Applies To
| DocuShare Release | Assessment |
| DocuShare 7.5 | Addressed by the Tomcat 9.0.120 patch. |
| DocuShare 7.6 | Addressed by the Tomcat 9.0.120 patch. |
| DocuShare 7.7 | Addressed by the Tomcat 9.0.120 patch. |
| DocuShare 8.0 | Addressed by the Tomcat 9.0.120 patch. |
| Important: If your environment includes custom Tomcat, connector, or TLS changes outside the standard Xerox DocuShare configuration, review those changes with Xerox DocuShare Support before applying the patch. |