Tomcat-catalina is vulnerable to privilege escalation. When JMX Remote Lifecycle Listener is used to configure Tomcat, a local attack is possible to access Tomcat process or configuration files and manipulate RMI registry, thereby allowing the attacker to act as man-in-the-middle (MitM) to steal the the credential for JMX interface and to get full control over JMX instance.
lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.html
tomcat.apache.org/security-7.html
tomcat.apache.org/security-8.html
tomcat.apache.org/security-9.html
github.com/apache/tomcat/commit/1fc9f58
github.com/apache/tomcat/commit/a91d7db
github.com/apache/tomcat/commit/bef3f40
lists.apache.org/thread.html/43530b91506e2e0c11cfbe691173f5df8c48f51b98262426d7493b67%40%3Cannounce.tomcat.apache.org%3E
lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d@%3Cdev.tomcat.apache.org%3E
lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0@%3Cdev.tomcat.apache.org%3E
lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9@%3Cdev.tomcat.apache.org%3E
lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E
lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a@%3Cdev.tomcat.apache.org%3E
lists.debian.org/debian-lts-announce/2020/01/msg00024.html
lists.debian.org/debian-lts-announce/2020/03/msg00029.html
seclists.org/bugtraq/2019/Dec/43
security.gentoo.org/glsa/202003-43
security.netapp.com/advisory/ntap-20200107-0001/
support.f5.com/csp/article/K10107360?utm_source=f5support&utm_medium=RSS
usn.ubuntu.com/4251-1/
www.debian.org/security/2019/dsa-4596
www.debian.org/security/2020/dsa-4680
www.oracle.com/security-alerts/cpuapr2020.html