When using FORM authentication there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
Created tomcat tracking bugs for this issue:
Affects: epel-all [bug 1785712]
Affects: fedora-all [bug 1785713]