In the process of becoming PCI complient, we we informed of the following CVE, any plans to upgrade Tomcat?
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3190
Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through...