Team,
We are currently using Jira Server Enterprise version 8.5.3. The bundled version of Apache Tomcat is 8.5.42. This version of Apache Tomcat is vulnerable. We read that the exploit is only possible if we are using an AJP connector, not the regular HTTP connector that is used by default in Jira.
However, we want to upgrade Apache tomcat version. Can someone please let us know if there will be issues if we upgrade Apache tomcat version. Also, can someone provide us the details on how to upgrade the bundled Apache tomcat version.