A number of flaws affect the version of Tomcat5 shipped with RHEL5. Please see linked bugs for details.
The fix had already been merged to the RHEL-5 branch and tagged. The corresponding backports were made to the 5.0.z branch and shipped as part of http://rhn.redhat.com/errata/RHSA-2007-0327.html.