Apache Tomcat versions prior to tomcat-4.1.24 create /opt/tomcat with a directory mode which allowed users to access files containing passwords.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31196/tomcat4.gentoo.txt
Source: https://packetstormsecurity.com/files/31196/tomcat4.gentoo.txt.html

