I'm not sure wether this affects our specific Linux versions but filing a bug to be sure.
java team, can you confirm ?
I can confirm that it works with 5.5.6-alpha1 (not in portage yet) and with the tomcat-5.0.27-r4 ebuild (latest stable in portage), after adding the "manager" role to the "tomcat" user in $CATALINA_HOME/conf/tomcat-users.xml I can't say if the patch works because I failed to apply it, though this is probably my fault.
Thanks Stefan for verifying. Java team, please test and patch ebuild with provided patch : http://www.mail-archive.com/tomcat-dev@jakarta.apache.org/msg66978.html This is really small (XSS needing authentication) so no GLSA needed.
It's small but should nevertheless be fixed...
trying to fix the bugger
patch fixed gentoo and committed, will be on mirrors soon. bumped to servletapi-2.4-r1
ppc64: please test and mark servletapi-2.4-r1 stable
stable on ppc64
Closed without GLSA