One of our clients has a security concern using the default installed version of Apache Tomcat that comes with Confluence 7.4.9 he said it's affected by multiple vulnerabilities as referenced in the vendor advisory and he's suggesting to upgrade to Apache Tomcat 9.0.43 or later, the same should be done for both Jira 8.13.8 and Confluence, any advice, please?
I did some research and I find that this could have an impact on the official support so when are you planning on supporting officially Tomcat 9?