Blog

IdentityIQ and Tomcat 9.0.106

Author

  • david_crow

    SailPoint

Tomcat is a commonly used application server in the customer-provided portion of an IdentityIQ deployment, and a number of recently announced security vulnerabilities in Tomcat (see https://tomcat.apache.org/security-9.html) has motivated many customers to update their Tomcat instances to version 9.0.106 and newer.

One of the changes introduced in Tomcat 9.0.106 is a limit on the number of parts in a multipart HTTP request to prevent potential denial of service issues. The default limit of 10 parts in 9.0.106 is lower than what is required for the batch file upload when creating a new batch request in IdentityIQ (manage/batchRequest/createBatchRequest.jsf). The default limit was increased in 9.0.107 and later to 50 which is sufficient for full compatibility with IdentityIQ.

Creating batch file requests in IdentityIQ with Tomcat 9.0.106 requires configuration to increase the multipart limits using the maxPartCount attribute of the <Connector> definition in conf/server.xml, but a more appropriate course of action is to upgrade Tomcat to a version newer than 9.0.106.