sk183615 - Check Point response to Apache Tomcat CVEs on Harmony Endpoint Security Management Server

Check Point response to Apache Tomcat CVEs on Harmony Endpoint Security Management Server

Solution

Check Point software uses the Apache Tomcat components only on the on-premises Security Management Server and only when the "Endpoint Policy Management" Software Blade is enabled.

The Apache Tomcat components are not directly exposed to external clients, eliminating the possibility of bypassing protections via direct access or malformed request paths.

This article does not list all the known CVEs for Apache Tomcat - only those that were explicitly checked by Check Point.

CVE Comment
2025
CVE-2025-31651 In the Check Point software, authentication is enforced at the Apache HTTP Server layer, so unauthenticated requests never reach Apache Tomcat.
This removes the primary condition needed to exploit these CVEs.
Nevertheless, Check Point integrated the relevant Apache Tomcat version that officially resolves these vulnerabilities in:
- Jumbo Hotfix Accumulator for R82 starting from Take 73
- Jumbo Hotfix Accumulator for R81.20 starting from Take 122
CVE-2025-31650

Article Properties

Access Level: General
Status: Approved
Date Created: 2025-07-07
Last Modified: 2026-02-18