Recently while working on a Android Web-App with Tomcat as a back-end , I discovered a bug in the CORS handling of Tomcat.
Please see the discussion of it on following links
StackOverflow
Tomcat Forums
Please see the discussion of it on following links
StackOverflow
Tomcat Forums