Apache has released security updates to address a vulnerability in Apache Tomcat that could allow a remote attacker to exploit the vulnerability and take control of the vulnerable machine.
The vulnerability exists in the CGI Servlet, due to the way it passes JRE commands to windows when running with enableCmdLineArguments enabled.
Apache fixes the vulnerability by disabling the CGI enableCmdLineArguments option by default. This vulnerability can be tracked as CVE-2019-0232.
The bug was discovered and reported to Apache by an external security researcher through the bug bounty.

The affected versions are:
- Apache Tomcat 9.0.0.M1 to 0.17
- Apache Tomcat 8.5.0 to 5.39
- Apache Tomcat 7.0.0 to 7.0.93
How to deal with it:
Apache recommends that users update to the following versions and ensure that the CGI Servlet initialization parameter enableCmdLineArguments is disabled.
- Upgrade to Apache Tomcat 9.0.18 or later
- Upgrade to Apache Tomcat 8.5.40 or later
- Upgrade to Apache Tomcat 7.0.93 or later
