CVE-2012-4431

Apache Tomcat < 6.0.36 - Access Control

Title source: rule

Description

org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.

Exploits (1)

nomisec STUB
by imjdl · poc
https://github.com/imjdl/CVE-2012-4431

References (25)

... and 5 more

Scores

EPSS 0.0982
EPSS Percentile 93.0%

Details

CWE
CWE-264
Status published
Products (37)
apache/tomcat 6.0
apache/tomcat 6.0.0 (2 CPE variants)
apache/tomcat 6.0.1 (2 CPE variants)
apache/tomcat 6.0.2 (3 CPE variants)
apache/tomcat 6.0.3
apache/tomcat 6.0.4 (2 CPE variants)
apache/tomcat 6.0.5
apache/tomcat 6.0.6 (2 CPE variants)
apache/tomcat 6.0.7 (3 CPE variants)
apache/tomcat 6.0.8 (2 CPE variants)
... and 27 more
Published Dec 19, 2012
Tracked Since Feb 18, 2026