Amazon Linux AMI : tomcat7 (ALAS-2018-1099)
Medium Nessus Plugin ID 118803
SynopsisThe remote Amazon Linux AMI host is missing a security update.
DescriptionWhen the default servlet in Apache Tomcat versions 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.(CVE-2018-11784)
SolutionRun 'yum update tomcat7' to update your system.