This will vary based on the vulnerability scanner used to scan VIOM, but these messages may indicate executable permissions of a file owned by root.
The vulnerability scanners are highlighting possible vulnerabilities present with these Apache Tomcat files owned by root with executable permissions.
The noted condition highlighted in this scan is resolved with VIOM 8.0.2 Patch 320.
The solution implemented was to change the root ownership to its own tomcat user and then clean up the permissions associated to these files.
Please upgrade to VIOM 8.0.2.320 or later to implement the required changes.