CERT reported to security@tomcat a flaw handling cookies containing a '
character. Tomcat currently treats it as a delimeter. This may well not be a
security issue in itself.
TC 6.0: http://svn.apache.org/viewvc?view=rev&rev=553218
TC 5.5: Affected.
TC 5.0: Affected. (Use $Version=1).
TC 4.1: Like 5.0
additional patch also needed, attached
Issue not yet public