A new Debian Linux update has been published: DSA 4627-1: tomcat9 security update
A tomcat9 security update has been released for Debian GNU/Linux 10 to address several vulnerabilities were discovered in the Tomcat servlet and JSP engine, which could result in code execution or denial of service.Read more @ Linux Compatible