Several issues were discovered in the Tomcat servlet and JSP engine. They could lead to unauthorized access to protected resources, denial-of-service, or information leak.
For the stable distribution (stretch), these problems have been fixed in version 8.5.14-1+deb9u3.
We recommend that you upgrade your tomcat8 packages.
Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/