Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
https://github.com/advisories/GHSA-86fp-jgwm-wgj5
https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1673
http://tomcat.apache.org/security-4.html
http://archives.neohapsis.com/archives/vuln-dev/2002-q3/0482.html