Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Can the embedded Tomcat be upgraded to 9.0.44 or does it need to remain on 8.5.xx?

Bill Zakrzewski
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
March 22, 2021

We have received a Cat 1 vulnerability for the current version of tomcat.  We have other products using Tomcat and wanted to try to keep them all on the same version of Apache Tomcat.   We just upgrade one product to apache 9.0.44 and wanted to know if Jira and Confluence can both be upgraded the same version without breaking the application.

1 answer

1 accepted

1 vote
Answer accepted
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
March 23, 2021

In theory, yes, you could pull the Jira or Confluence out of the Tomcat and push it into another one.

But I'm afraid Atlassian don't support that and it's not a simple redeployment, it is quite a lot of work. 

I also have a couple of third-hand reports from people who have tried to redeploy Jira on to Tomcat 9 have met with simple failure - the application won't start (Tomcat runs, but can't start Jira)

So, we're stuck on Jira.  But there's better news on Confluence - later versions are bundled with Tomcat 9, so a standard upgrade will make the problem go away.

For Jira, upgrading might fix it, if the vulnerability is limited to specific 8.5.x versions - see https://confluence.atlassian.com/jiracore/bundled-tomcat-and-java-versions-1013854250.html  but for Confluence, an upgrade to 6.10 or higher takes the Tomcat up to 9.  Similar page for Confluence is https://confluence.atlassian.com/doc/bundled-tomcat-and-java-versions-1005786018.html

Suggest an answer

Log in or Sign up to answer