I think we can all agree that making you app less vulnerable online is a high priority. One of the ways is to update the Tomcat web server.
I've replaced the out-of-box Tomcat 6.035 with 6.037 and now with the newly released 6.039 64bit. Replacing 6.035 simply means downloading the latest version and overwriting the existing files in AwareIM/Tomcat/ directory.
I've been using 6.037 for quite while and now 6.039 without a hiccup.
NOTE: Don't forget to replace the tools.jar in the Tomcat/lib directory with the one form AwareIM/JDK directory (if you have updated JDK), as well as the latest mysql-connector.jar
http://tomcat.apache.org/download-60.cgi
There are about 12 vulnerabilities fixed since ver 6.035 ranging including denial of service, information disclosure, Session fixation, Bypass of security constraints and more.
https://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.39
Cheers