CVE-2012-4431

Apache Tomcat 6.x < 6.0.36 and 7.x < 7.0.32 - CSRF Protection Bypass via Sessionless Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-4431. PoCs published by imjdl.

AI-analyzed exploit summary The repository appears to be a partial or mislabeled Apache Tomcat distribution without any exploit code or proof-of-concept for CVE-2012-4431. It lacks any offensive techniques or vulnerability-specific payloads.

Description

org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.

Exploits (1)

nomisec STUB
by imjdl · poc
https://github.com/imjdl/CVE-2012-4431

The repository appears to be a partial or mislabeled Apache Tomcat distribution without any exploit code or proof-of-concept for CVE-2012-4431. It lacks any offensive techniques or vulnerability-specific payloads.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Apache Tomcat
No auth needed
Prerequisites: None identified
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (25)

Core 25
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0268.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0648.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1437.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0647.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1853.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0267.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18541
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=136612293908376&w=2
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-12/0045.html
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-01/msg00051.html
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1685-1
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2012-12/msg00089.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/56814
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-01/msg00080.html
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-7.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1027834
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-6.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57126
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-01/msg00037.html
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=139344343412337&w=2
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2012-12/msg00090.html

Scores

EPSS 0.0982
EPSS Percentile 93.2%

Details

CWE
CWE-264
Status published
Products (37)
apache/tomcat 6.0
apache/tomcat 6.0.0 (2 CPE variants)
apache/tomcat 6.0.1 (2 CPE variants)
apache/tomcat 6.0.2 (3 CPE variants)
apache/tomcat 6.0.3
apache/tomcat 6.0.4 (2 CPE variants)
apache/tomcat 6.0.5
apache/tomcat 6.0.6 (2 CPE variants)
apache/tomcat 6.0.7 (3 CPE variants)
apache/tomcat 6.0.8 (2 CPE variants)
... and 27 more
Published Dec 19, 2012
Tracked Since Feb 18, 2026