By simply sending HTTP requests, attackers can trigger the deserialisation of malicious data in Tomcat's session storage and gain control.
Fiona Jackson
Source: TechRepublic
Source Link: https://www.techrepublic.com/article/news-apache-tomcat-vulnerability/