J
JosephB
Guest
I see that the Tomcat service is running as the system administrator, which grants the Tomcat service root access. While testing Tomcat I also found that through your applications you can actually write to any folder on the drive. Is this not a major security risk? What steps must I take to secure Tomcat and possibly set the service to use a restricted user account?