Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.
http://www.securityfocus.com/bid/74265
http://www.debian.org/security/2015/dsa-3278
http://rhn.redhat.com/errata/RHSA-2015-1642.html
http://rhn.redhat.com/errata/RHSA-2015-1641.html
http://rhn.redhat.com/errata/RHSA-2015-0849.html
http://rhn.redhat.com/errata/RHSA-2015-0848.html