The Apache Tomcat Security Team rates the impact of each security flaw
that affects Tomcat. We've chosen a rating scale quite similar to those
used by other major vendors in order to be consistent. Basically the goal
of the rating system is to answer the question "How worried should I be
about this vulnerability?".
Note that the rating chosen for each flaw is the worst possible case
across all architectures. To determine the exact impact of a particular
vulnerability on your own systems you will still need to read the security
advisories to find out more about the flaw.
We use the following descriptions to decide on the impact rating to give
each vulnerability: