LTS security update

Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine.

WARNING: The fix for CVE-2020-1938 may disrupt services that rely on a working AJP configuration. The option secretRequired defaults to true now. You should define a secret in your server.xml or you can revert back by setting secretRequired to false.

# do not modify the following line #include "$(ENGLISHDIR)/lts/security/2020/dla-2209.data" # $Id: $