org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tomcat | Apache | 6.0 (including) | 6.0 (including) |
Tomcat | Apache | 6.0.0 (including) | 6.0.0 (including) |
Tomcat | Apache | 6.0.0-alpha (including) | 6.0.0-alpha (including) |
Tomcat | Apache | 6.0.1 (including) | 6.0.1 (including) |
Tomcat | Apache | 6.0.1-alpha (including) | 6.0.1-alpha (including) |
Tomcat | Apache | 6.0.2 (including) | 6.0.2 (including) |
Tomcat | Apache | 6.0.2-alpha (including) | 6.0.2-alpha (including) |
Tomcat | Apache | 6.0.2-beta (including) | 6.0.2-beta (including) |
Tomcat | Apache | 6.0.3 (including) | 6.0.3 (including) |
Tomcat | Apache | 6.0.4 (including) | 6.0.4 (including) |
Tomcat | Apache | 6.0.4-alpha (including) | 6.0.4-alpha (including) |
Tomcat | Apache | 6.0.5 (including) | 6.0.5 (including) |
Tomcat | Apache | 6.0.6 (including) | 6.0.6 (including) |
Tomcat | Apache | 6.0.6-alpha (including) | 6.0.6-alpha (including) |
Tomcat | Apache | 6.0.7 (including) | 6.0.7 (including) |
Tomcat | Apache | 6.0.7-alpha (including) | 6.0.7-alpha (including) |
Tomcat | Apache | 6.0.7-beta (including) | 6.0.7-beta (including) |
Tomcat | Apache | 6.0.8 (including) | 6.0.8 (including) |
Tomcat | Apache | 6.0.8-alpha (including) | 6.0.8-alpha (including) |
Tomcat | Apache | 6.0.9 (including) | 6.0.9 (including) |
Tomcat | Apache | 6.0.9-beta (including) | 6.0.9-beta (including) |
Tomcat | Apache | 6.0.10 (including) | 6.0.10 (including) |
Tomcat | Apache | 6.0.11 (including) | 6.0.11 (including) |
Tomcat | Apache | 6.0.12 (including) | 6.0.12 (including) |
Tomcat | Apache | 6.0.13 (including) | 6.0.13 (including) |
Tomcat | Apache | 6.0.14 (including) | 6.0.14 (including) |
Tomcat | Apache | 6.0.15 (including) | 6.0.15 (including) |
Tomcat | Apache | 6.0.16 (including) | 6.0.16 (including) |
Tomcat | Apache | 6.0.17 (including) | 6.0.17 (including) |
Tomcat | Apache | 6.0.18 (including) | 6.0.18 (including) |
Tomcat | Apache | 6.0.19 (including) | 6.0.19 (including) |
Tomcat | Apache | 6.0.20 (including) | 6.0.20 (including) |
Tomcat | Apache | 6.0.24 (including) | 6.0.24 (including) |
Tomcat | Apache | 6.0.26 (including) | 6.0.26 (including) |
Tomcat | Apache | 6.0.27 (including) | 6.0.27 (including) |
Tomcat | Apache | 6.0.28 (including) | 6.0.28 (including) |
Tomcat | Apache | 6.0.29 (including) | 6.0.29 (including) |
Tomcat | Apache | 6.0.30 (including) | 6.0.30 (including) |
Tomcat | Apache | 6.0.31 (including) | 6.0.31 (including) |
Tomcat | Apache | 6.0.32 (including) | 6.0.32 (including) |
Tomcat | Apache | 6.0.33 (including) | 6.0.33 (including) |
Tomcat | Apache | 6.0.35 (including) | 6.0.35 (including) |
JBoss Data Grid 6.1 | RedHat | * | |
Red Hat JBoss Enterprise Application Platform 6.0 | RedHat | * | |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 | RedHat | jbossweb-0:7.0.17-4.Final_redhat_3.ep6.el5 | * |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 | RedHat | jbossweb-0:7.0.17-4.Final_redhat_3.ep6.el6 | * |
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | RedHat | tomcat6-0:6.0.35-6_patch_06.ep6.el5 | * |
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | RedHat | tomcat7-0:7.0.30-3_patch_02.ep6.el5 | * |
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | RedHat | tomcat6-0:6.0.35-29_patch_06.ep6.el6 | * |
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | RedHat | tomcat7-0:7.0.30-5_patch_02.ep6.el6 | * |
Red Hat JBoss Operations Network 3.2 | RedHat | * | |
Red Hat JBoss Portal Platform 6.1 | RedHat | * | |
Red Hat JBoss Web Server 2.0 | RedHat | * | |
Red Hat JBoss Web Server 2.0 | RedHat | * | |
Tomcat6 | Ubuntu | oneiric | * |
Tomcat6 | Ubuntu | precise | * |
Tomcat6 | Ubuntu | quantal | * |
Tomcat6 | Ubuntu | upstream | * |
Tomcat7 | Ubuntu | oneiric | * |
Tomcat7 | Ubuntu | precise | * |
Tomcat7 | Ubuntu | quantal | * |
Tomcat7 | Ubuntu | upstream | * |