Anyone know if there is a fix for this yet?

For cve-2007-4465 tomcat multiple xss vulnerability-

"The only systems affected are those where the"AddDefaultCharset" directive has been removed, and are using directory indexes."
and to my knowledge, this is not the case with any of our servers.

Potential Security Vulnerability with Apache