Apache Tomcat Patch: Upgrade to Tomcat 9.0.120 for Xerox DocuShare
| Summary: This release upgrades the Apache Tomcat web container bundled with DocuShare from version 9.0.106 to version 9.0.120. It is delivered as a set of standalone patch bundles for DocuShare 7.5, 7.6, 7.7, and 8.0. |
Overview
This release upgrades the Apache Tomcat web container bundled with DocuShare from version 9.0.106 to version 9.0.120. It is intended to help customers clear version-based findings reported by vulnerability scanners and to resolve the Apache Tomcat security advisories published against Tomcat versions 9.0.107 through 9.0.120.
The patch keeps the DocuShare Tomcat implementation aligned with the supported Apache Tomcat 9.0.120 level, without requiring any application changes.
What This Release Delivers
- Replaces the bundled Apache Tomcat 9.0.106 installation with Apache Tomcat 9.0.120.
- Resolves the Apache Tomcat security advisories published against Tomcat 9.0.107 through 9.0.120.
- Clears the version-based findings that vulnerability scanners report against Tomcat 9.0.106.
- Keeps DocuShare aligned with the supported Apache Tomcat 9.0.120 level without requiring application changes.
Patch Bundles
Apply the patch bundle that matches your DocuShare release. Each bundle is standalone and cannot be installed on a different DocuShare version.
| DocuShare Release | Patch Bundle |
| DocuShare 7.5 | ds750-tomcat9.0.120 - https://docushare.xerox.com/doug/dsweb/View/Collection-20223 |
| DocuShare 7.6 | ds760-tomcat9.0.120 - https://docushare.xerox.com/doug/dsweb/View/Collection-20222 |
| DocuShare 7.7 | ds770-tomcat9.0.120 - https://docushare.xerox.com/doug/dsweb/View/Collection-20221 |
| DocuShare 8.0 | ds800-tomcat9.0.120 - https://docushare.xerox.com/doug/dsweb/View/Collection-20220 |
Each bundle is supplied as a Windows .zip archive and a Linux .tar.gz archive.
System Requirements
This patch can only be installed on an existing DocuShare 7.5, 7.6, 7.7, or 8.0 system. Refer to the appropriate version release notes for upgrade paths and system requirements.
Installation Procedure
1. Back up your DocuShare installation, including the tomcat directory and the server.xml file.
2. Stop the DocuShare services.
3. Extract the archive for your platform, run dsUpdate (or dsUpdate.exe on Windows), and accept the license agreement.
4. Start the DocuShare services.
5. Confirm the upgrade by checking the version reported in the tomcat/RELEASE-NOTES file of your DocuShare installation.
6. Review server.xml and re-apply any site-specific customizations, such as connector ports, TLS settings, or custom valves.
Each patch bundle also includes the DocuShare installation guide, which provides the complete installation procedure.
Bug Fixes in this Release
| AR Number | SPAR Number | Description |
| 55662 | 4141 | In an approval workflow with more than one approver, a content rule using the (PS) Assign Routing Data action did not populate the fields for the second approver, and that approver's comments were not added. |
| 65238 | 6165 | Scanning from a Xerox ConnectKey device failed when SAML authentication was enabled on the DocuShare server. |
| 82184 | 7666 | In ConnectKey, the "Scan another document" link shown after a scan completed was not clickable, so a further scan could not be started from that page. |
|
83451 84665 |
8443 | Cutting, pasting or deleting documents and collections could stop responding, and the server had to be restarted to recover. This has been corrected. |
| Various security fixes. |
Known Issues
| AR Number | Description | Work Around |
| 85751 | On systems with Content Encryption enabled, documents added after Content Encryption was turned on may not be returned by content (full-text) searches. Property and metadata searches are not affected, and documents indexed before Content Encryption was enabled remain searchable, so the condition may not be immediately apparent. This affects systems upgraded from an earlier DocuShare release. New installations are not affected. |
Add the content encryption library to the Index Server classpath: 1. Stop DocuShare. 2. In <DSHome>\config\Monitor.xml, locate the <Server> block whose <Name> is IndexServer, and append ;+DSH+\lib\cryptoContent.jar to the <StartJVMClassPath> element within that block. 3. Save the file and restart DocuShare. 4. Confirm the change took effect. The effective classpath is written to Monitor.log each time the JVM launches, and the dsix command line must now list cryptoContent.jar. 5. Only after step 4 is confirmed, re-index the affected content. The classpath change is not retroactive. Do not re-index before step 4 is confirmed. Re-indexing while content is still unreadable re-adds the affected documents with metadata only, which removes the extracted text of documents that were previously searchable. |
No specific known issues are listed in this release note. For the latest information, refer to the current DocuShare documentation and Knowledge Base articles.
Additional Information and Support
For the latest documentation and product updates, refer to the DocuShare website and Knowledge Base. For troubleshooting or product guidance, contact Xerox support.
After installation, review any environment-specific Tomcat settings in server.xml to confirm that custom configurations remain in place and that the patch does not override site-specific changes.