CVE Vulnerabilities

CVE-2012-4431

Published: Dec 19, 2012 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.

Affected Software

Name Vendor Start Version End Version
Tomcat Apache 6.0 (including) 6.0 (including)
Tomcat Apache 6.0.0 (including) 6.0.0 (including)
Tomcat Apache 6.0.0-alpha (including) 6.0.0-alpha (including)
Tomcat Apache 6.0.1 (including) 6.0.1 (including)
Tomcat Apache 6.0.1-alpha (including) 6.0.1-alpha (including)
Tomcat Apache 6.0.2 (including) 6.0.2 (including)
Tomcat Apache 6.0.2-alpha (including) 6.0.2-alpha (including)
Tomcat Apache 6.0.2-beta (including) 6.0.2-beta (including)
Tomcat Apache 6.0.3 (including) 6.0.3 (including)
Tomcat Apache 6.0.4 (including) 6.0.4 (including)
Tomcat Apache 6.0.4-alpha (including) 6.0.4-alpha (including)
Tomcat Apache 6.0.5 (including) 6.0.5 (including)
Tomcat Apache 6.0.6 (including) 6.0.6 (including)
Tomcat Apache 6.0.6-alpha (including) 6.0.6-alpha (including)
Tomcat Apache 6.0.7 (including) 6.0.7 (including)
Tomcat Apache 6.0.7-alpha (including) 6.0.7-alpha (including)
Tomcat Apache 6.0.7-beta (including) 6.0.7-beta (including)
Tomcat Apache 6.0.8 (including) 6.0.8 (including)
Tomcat Apache 6.0.8-alpha (including) 6.0.8-alpha (including)
Tomcat Apache 6.0.9 (including) 6.0.9 (including)
Tomcat Apache 6.0.9-beta (including) 6.0.9-beta (including)
Tomcat Apache 6.0.10 (including) 6.0.10 (including)
Tomcat Apache 6.0.11 (including) 6.0.11 (including)
Tomcat Apache 6.0.12 (including) 6.0.12 (including)
Tomcat Apache 6.0.13 (including) 6.0.13 (including)
Tomcat Apache 6.0.14 (including) 6.0.14 (including)
Tomcat Apache 6.0.15 (including) 6.0.15 (including)
Tomcat Apache 6.0.16 (including) 6.0.16 (including)
Tomcat Apache 6.0.17 (including) 6.0.17 (including)
Tomcat Apache 6.0.18 (including) 6.0.18 (including)
Tomcat Apache 6.0.19 (including) 6.0.19 (including)
Tomcat Apache 6.0.20 (including) 6.0.20 (including)
Tomcat Apache 6.0.24 (including) 6.0.24 (including)
Tomcat Apache 6.0.26 (including) 6.0.26 (including)
Tomcat Apache 6.0.27 (including) 6.0.27 (including)
Tomcat Apache 6.0.28 (including) 6.0.28 (including)
Tomcat Apache 6.0.29 (including) 6.0.29 (including)
Tomcat Apache 6.0.30 (including) 6.0.30 (including)
Tomcat Apache 6.0.31 (including) 6.0.31 (including)
Tomcat Apache 6.0.32 (including) 6.0.32 (including)
Tomcat Apache 6.0.33 (including) 6.0.33 (including)
Tomcat Apache 6.0.35 (including) 6.0.35 (including)
JBoss Data Grid 6.1 RedHat *
Red Hat JBoss Enterprise Application Platform 6.0 RedHat *
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 RedHat jbossweb-0:7.0.17-4.Final_redhat_3.ep6.el5 *
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 RedHat jbossweb-0:7.0.17-4.Final_redhat_3.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat tomcat6-0:6.0.35-6_patch_06.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat tomcat7-0:7.0.30-3_patch_02.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat tomcat6-0:6.0.35-29_patch_06.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat tomcat7-0:7.0.30-5_patch_02.ep6.el6 *
Red Hat JBoss Operations Network 3.2 RedHat *
Red Hat JBoss Portal Platform 6.1 RedHat *
Red Hat JBoss Web Server 2.0 RedHat *
Red Hat JBoss Web Server 2.0 RedHat *
Tomcat6 Ubuntu oneiric *
Tomcat6 Ubuntu precise *
Tomcat6 Ubuntu quantal *
Tomcat6 Ubuntu upstream *
Tomcat7 Ubuntu oneiric *
Tomcat7 Ubuntu precise *
Tomcat7 Ubuntu quantal *
Tomcat7 Ubuntu upstream *

References