Re: False Positive Vulnerabilities in el-api.jar from Official Apache Tomcat Distribution

"Piotr P. Karwasz" <[email protected]>
Newsgroups gmane.comp.jakarta.tomcat.user
Message-ID <[email protected]>
Hi Sathish,

On 10.11.2025 12:10, S Sathish S wrote:
> Tomcat-el-api.jar
> Identifiers
> 
>   *   cpe:2.3:a:apache:tomcat:6.0.0:*:*:*:*:*:*:*  (Confidence:Medium)  suppress
>   *   cpe:2.3:a:apache_tomcat:apache_tomcat:11.0.10:*:*:*:*:*:*:*  (Confidence:Low)  suppress


The results you’re seeing are most likely caused by an issue with the
hash-based analyzer. This can happen if:

- Dependency-Check is running in offline mode,
- the `analyzer.central.enabled` property is set to `false`, or
- the `el-api.jar` file has been modified, as mentioned in [1].

In any of these cases, neither Dependency-Check nor Tomcat can correct
the results.

Piotr

[1] https://lists.apache.org/thread/0smk8r2czoqprb68yq4hvo0vdhrq52w0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.