> That's not a super-secure solution. You really should specify a
> correct whitelist pattern instead of "accept all".

thanks for your comment.
You are fully right, but as this seem to will be fixed with the next
tomcat version, I see it only as a temporary work-around.

After the new version is released the configuration option can be
completely removed again.

I'm not sure if it is worth to find the correct options you have to
allow, as tomcat does not log any reason why the connection was refused.



"Programming today is a race between software engineers striving to
build bigger and better idiot-proof programs, and the universe trying to
produce bigger and better idiots. So far, the universe is winning." --
Rich Cook

