Customer requests backport for Tomcat known issue:
https://bz.apache.org/bugzilla/show_bug.cgi?id=63311
They have tested the proposed workaround:
org.apache.catalina.STRICT_SERVLET_COMPLIANCE=false
It works for them but they feel that it compromises some level of security.
- links to