[Blog](/blog)

Show links

Resources

[Blog](/blog)

[Breaches](/breaches)

[eBooks, reports, & more](/resources)

[Events](/events)

[News](/news)

[Attack Surface Management](/category/attack-surface-management)

Show links

Categories

[Attack Surface Management](/category/attack-surface-management)

[Company News](/category/company-news)

[Compliance and Regulations](/category/compliance-and-regulations)

[Cybersecurity](/category/cybersecurity)

[Data Breaches](/category/data-breaches)

[DevOps](/category/devops)

[Human Cyber Risk](/category/human-cyber-risk)

[Risks and Vulnerabilities](/category/risks-and-vulnerabilities)

[Third-Party Risk Management](/category/third-party-risk-management)

[Vendor Risk Management](/category/vendor-risk-management)

[How to Secure Apache Tomcat 8 in 15 Steps](/blog/15-ways-to-secure-apache-tomcat-8)

Publish date

January 8, 2025

{x} minute read

# How to Secure Apache Tomcat 8 in 15 Steps

[Get a demo](/contact-sales)

[Free trial](/demo)

[Download the PDF guide](/resources/complete-guide-to-data-breaches)

[Free trial](/demo)

Written by

[Abi Tyas Tunggal](/team/abi-tyas-tunggal)

Writer and Senior Product Manager at UpGuard.

Abi's work has influenced leaders across cybersecurity, technology, and financial services.

Reviewed by

[Kaushik Sen](/team/kaushik-sen)

Chief Marketing Officer

Kaushik has a background in software engineering, enterprise solution architecture, and data analytics. He brings a unique, data-driven perspective to cybersecurity education.

Table of contents

eBook

A Complete Guide to Data Breaches

Free resource

### A Complete Guide to Data Breaches

Learn how to avoid a costly data breach with a comprehensive prevention strategy.

[Download now](/resources/complete-guide-to-data-breaches)

Apache Tomcat is the leading Java application server by market share and the world's most widely used web application server overall. Currently at version 8, the popular web server has not been without its security flaws, perhaps most famously publicized [in this incident](https://www.businessinsider.com/plane-hacker-talks-about-plane-hacking-at-grrcon-2012-2015-5) of aircraft hacking by security researcher Chris Roberts earlier this year. However, hardening Tomcat's default configuration is just plain good security sense—even if you don't plan on using it on your plane's network. The following are 15 way to secure Apache Tomcat 8, out-of-the-box.

## 1. Don't Run Tomcat as the Root User

This line of advice applies to most web server platforms. Web-related services should not be run by user accounts with a high level of administrative access. In Tomcat's case, a user with the minimum necessary OS permissions should be created exclusively to run the Tomcat process.

## 2. Remove Any Default Sample or Test Web Applications

Most web server platforms also provide a set of sample or test web application for demo and learning purposes. These applications have been known to harbor [vulnerabilities](/blog/vulnerability), and should be removed if not in use. Tomcat's examples web application is an application that should be removed to prevent exploitation.

## 3. Put Tomcat's Shutdown Procedure on Lockdown

This prevents malicious actors from shutting down Tomcat's web services. Either disable the shutdown port by setting the **port** attribute in the **server.xml** file to **-1**. If the port must be kept open, be sure to configure a strong password for shutdown.

## 4. Disable Support for TRACE Requests

Though useful for debugging, enabling **allowTrace** can expose some browsers to an [cross-site scripting XSS attack](/blog/cross-site-scripting-xss). This can be mitigated by disabling allowTrace in the **server.xml** file.

## 5. Disable Sending of the X-Powered-By HTTP Header

If enabled, Tomcat will send information such as the Servlet and JSP specification versions and the full Tomcat version, among others. This gives attackers a workable starting point to craft an attack. To prevent this information leakage, disable the **xpoweredBy** attribute in the **server.xml** file.

## 6. Disable SSLv3 to Prevent POODLE Attacks

POODLE is a [SSL](/blog/ssl-certificate) v3 protocol vulnerability discovered in 2014. An attacker can gain access to sensitive information such as passwords and browser cookies by exploiting this vulnerability; subsequently, SSL v3 (and SSL in general) should not be included in **server.xml file&#xA0;**&#x75;nder the **sslEnabledProtocols&#xA0;**&#x61;ttribute.

## 7. Set the DeployXML Attribute to False in a Hosted Environment

The prevents would-be attackers from attempting to increase privileges to a web application by packaging an altered/custom context.xml. This is especially critical in hosted environments where other web applications sharing the same server resources cannot be trusted.

## 8. Configure and Use Realms Judiciously

Tomcat's realms are designed differently and their limitations should be understood before use. For example, the **DataSourceRealm** should be used in place of the **JDBCRealm**, as the latter is single threaded for all authentication/authorization options and not suited for production use. The  **JAASRealm&#x20;**&#x73;hould also be avoided, as it is seldom used and sports an immature codebase.

## 9. Set Tomcat to Create New Facade Object for Each Request

This can be configured by setting the **org.apache.catalina.connector.RECYCLE\_FACADES** system property to **true**. By doing this, you reduce the chance of a buggy application exposing data between requests.

## 10. Ensure that Access to Resources is Set to Read-Only

This can be done by setting **readonly** to **true** unde&#x72;**&#xA0;DefaultServlet,&#x20;**&#x65;ffectively preventing clients from deleting/modifying static resources on the server and uploading new resources.

## 11. Disable Tomcat from Displaying Directory Listings

Listing the contents of directories with a large number of files can consume considerable system resources, and can therefore be used in a denial-of-service (DoS) attack. Setting **listings** t&#x6F;**&#x20;false&#x20;**&#x75;nde&#x72;**&#x20;DefaultServlet&#x20;**&#x6D;itigates this risk.

## 12. Enable Logging of Network Traffic

In general, logs should generated and maintained on all levels (e.g., user access, Tomcat internals, et al), but network traffic logging is especially useful for breach assessment and forensics. To set up your Tomcat application to create logs of network traffic, use/configure the **AccessLogValve** component.

## 13. Disable Automated Deployment if Not in Use

If you're running a fully-realized CI/CD pipeline, good for you—you'll need full use of Tomcat's host components. However, if not—be sure to set all the host attributes to **false&#x20;**(**autoDeploy, deployOnStartup,&#x20;**&#x61;n&#x64;**&#x20;deployXML**) to prevent them from being compromised by an attacker.

## 14. Disable or Limit the Tomcat Manager Webapp

Tomcat Manager enables easy configuration and management of Tomcat instances through one web interface. Convenient, no doubt—for both authorized administrators and attackers. Alternative methods for administering Tomcat instances are therefore better, but if Tomcat Manager must be used, be sure to use its configuration options to limit your risk exposure.

## 15. Limit the Availability of Connectors

Connectors by default listen to all interfaces. For better security, they should only listen to those required by your web application and ignore the rest. This can be accomplished by setting the **address** attribute of the connector element.

In short, Apache Tomcat's popularity invariably means that its vulnerabilities and exploits are well known by both security professionals and malicious actors alike. Out-of-the-box security is never sufficient for protecting against today's [cyber threats](https://www.upguard.com/blog/cyber-threat), and proper hardening of Tomcat is especially critical given the server platform's ubiquity. Looking for a way to perform these hardening checks and more, automatically—with just a few mouse clicks? Check out ScriptRock's platform for vulnerability detection and security monitoring. It's free for up to 10 servers, so try it today on us.

### Sources

<https://www.owasp.org/index.php/Securing_tomcat>

<https://tomcat.apache.org/tomcat-8.0-doc/security-howto.html>

<https://www.mulesoft.com/tcat/tomcat-security>

<https://www.businessinsider.com/plane-hacker-talks-about-plane-hacking-at-grrcon-2012-2015-5>

eBook

A Complete Guide to Data Breaches

Free resource

### A Complete Guide to Data Breaches

Learn how to avoid a costly data breach with a comprehensive prevention strategy.

[Download now](/resources/complete-guide-to-data-breaches)

## Related posts

Learn more about the latest issues in cybersecurity.

Attack Surface Management

#### [Find Out if You're Exposed on the Dark Web](/blog/find-out-if-youre-exposed-on-the-dark-web)

Answer 5 quick questions to predict what a dark web scan will find about your company. Then run the free scan to see your real exposure.

[](/team/lance-turner)

[Lance Turner](#)

September 28, 2026

Data Breaches

#### [Your First Dark Web Scan Report, Explained](/blog/your-first-dark-web-scan-report-explained)

You scanned your domain. What do the results mean?

[](/team/lance-turner)

[Lance Turner](#)

September 21, 2026

Cybersecurity

#### [12 Cybersecurity Horror Stories of 2026 (No Costume Required)](/blog/cybersecurity-horror-stories-2026)

A warning ignored once becomes a headline. Read more about these 12 real 2026 cybersecurity incidents, and the sign each one gave before it made the news.

[](/team/revashni-moodley)

[Revashni Moodley](#)

September 28, 2026

Data Breaches

#### [Good Security Rating? Your Dark Web Exposure Says Otherwise](/blog/good-security-rating-your-dark-web-exposure-says-otherwise)

Scan your domain to see just how exposed you are on the Dark Web.

[](/team/lance-turner)

[Lance Turner](#)

September 20, 2026

Cybersecurity

#### [Left Unsupervised: 10 Times Access Outlived Its Authorization](/blog/10-times-access-outlived-authorization)

Access granted once shouldn’t mean access forever. Read more on how unmonitored access caused 10 of these real-life breaches and what they taught us.

[](/team/revashni-moodley)

[Revashni Moodley](#)

August 25, 2026

Cybersecurity

#### [Surviving a LockBit Ransomware Attack: The ROI of Visibility](/blog/surviving-a-lockbit-ransomware-attack)

Read how veteran CISO Nick Gicinto saved his alma mater from a LockBit ransomware attack by discarding the standard playbook.

[](/team/nicholas-sollitto)

[Nicholas Sollitto](#)

June 1, 2026

[All posts](/blog)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](/contact-sales)

[Free trial](/demo)
