Upgrade path for tomcat and java?

Upgrade path for tomcat and java?

Based on information from my cybersecurity department, the version of tomcat that PMP uses is 3 major revisions behind and has nearly 40 published vulnerabilities. Also the version of java is out of date.

Is there a recommended update path for tomcat and java?
                New to ADManager Plus?

                  New to ADSelfService Plus?