According to http://tomcat.apache.org/security-5.html Fixed in Apache Tomcat 5.5.17 Information disclosure CVE-2007-1858 The default SSL configuration permitted the use of insecure cipher suites including the anonymous cipher suite. The default configuration no longer permits the use of insecure cipher suites. Affects: 5.0.0-5.0.HEAD, 5.5.0-5.5.17
advisory text: "The default Tomcat configuration permitted the use of insecure SSL cipher suites including the anonymous cipher suite. (CVE-2007-1858)"
Please see https://access.redhat.com/security/cve/CVE-2007-1858 for a list of other products that contain this fix.