Apache Tomcat versions prior to 9.0.12, 8.5.34, and 7.0.91 are prone to an open-redirection vulnerability because it fails to properly sanitize user-supplied input.
id: CVE-2018-11784
info:
name: Apache Tomcat - Open Redirect
author: geeknik
severity: medium
...