> Source: [sk183615](https://support.checkpoint.com/results/sk/sk183615)

# sk183615 - Check Point response to Apache Tomcat CVEs on Harmony Endpoint Security Management Server

| Property | Value |
|----------|-------|
| Solution ID | sk183615 |
| Date Created | 2025-07-07 |
| Last Modified | 2026-02-18 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X, R82.20, R82.10, R82, R81.20 |
| OS | Gaia |

## Solution

Check Point software uses the Apache Tomcat components only on the on-premises Security Management Server and only when the "Endpoint Policy Management" Software Blade is enabled.

The Apache Tomcat components are not directly exposed to external clients, eliminating the possibility of bypassing protections via direct access or malformed request paths.

This article does not list all the known CVEs for Apache Tomcat - only those that were explicitly checked by Check Point.

|-------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| CVE                                                               | Comment                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **2025**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| [CVE-2025-31651](https://www.cve.org/CVERecord?id=CVE-2025-31651) | In the Check Point software, authentication is enforced at the Apache HTTP Server layer, so unauthenticated requests never reach Apache Tomcat. This removes the primary condition needed to exploit these CVEs. Nevertheless, Check Point integrated the relevant Apache Tomcat version that officially resolves these vulnerabilities in: * [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 73 * [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 122 |
| [CVE-2025-31650](https://www.cve.org/CVERecord?id=CVE-2025-31650) | In the Check Point software, authentication is enforced at the Apache HTTP Server layer, so unauthenticated requests never reach Apache Tomcat. This removes the primary condition needed to exploit these CVEs. Nevertheless, Check Point integrated the relevant Apache Tomcat version that officially resolves these vulnerabilities in: * [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 73 * [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 122 |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
