Our 3rd party ASV is detecting an incident against our self hosted Bitbucket Server instance:
Apache Tomcat AJP RCE Vulnerability (Ghostcat)
According to an article I found, the AJP connector service can be disabled by commenting out or removing the appropriate line from the $CATALINA_HOME/conf/server.xml file and restarting Tomcat.
Based on my understanding, Tomcat is embedded as part of Bitbucket Server and not a seperate install so how can this service be disabled?