In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade RHEL:7 tomcat-admin-webapps to version 0:7.0.76-11.el7_6 or higher.
This issue was patched in RHSA-2021:0882.
Note: Versions mentioned in the description apply only to the upstream tomcat-admin-webapps package and not the tomcat-admin-webapps package as distributed by RHEL.
See How to fix? for RHEL:7 relevant fixed versions and status.
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.