A new Debian Linux update has been published: DSA 4596-1: tomcat8 security update
A tomcat8 security update has been released for Debian GNU/Linux 9. Several issues were discovered in the Tomcat servlet and JSP engine, which could result in session fixation attacks, information disclosure, cross- site scripting, denial of service via resource exhaustion and insecure redirects.Read more @ Linux Compatible