CVE-2012-4431
Apache Tomcat < 6.0.36 - Access Control
Title source: ruleDescription
org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.
Exploits (1)
References (25)
... and 5 more
Scores
EPSS
0.0982
EPSS Percentile
93.0%
Details
CWE
CWE-264
Status
published
Products (37)
apache/tomcat
6.0
apache/tomcat
6.0.0 (2 CPE variants)
apache/tomcat
6.0.1 (2 CPE variants)
apache/tomcat
6.0.2 (3 CPE variants)
apache/tomcat
6.0.3
apache/tomcat
6.0.4 (2 CPE variants)
apache/tomcat
6.0.5
apache/tomcat
6.0.6 (2 CPE variants)
apache/tomcat
6.0.7 (3 CPE variants)
apache/tomcat
6.0.8 (2 CPE variants)
... and 27 more
Published
Dec 19, 2012
Tracked Since
Feb 18, 2026