By simply sending HTTP requests, attackers can trigger the deserialisation of malicious data in Tomcat’s session storage and gain control.
First seen on techrepublic.com
Jump to article: www.techrepublic.com/article/news-apache-tomcat-vulnerability/