Vulnerability Database

296,733

Total vulnerabilities in the database

CVE-2012-4431

org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software From Fixed in
apache / tomcat 6.0.33 6.0.33.x
apache / tomcat 6.0.0-alpha 6.0.0-alpha.x
apache / tomcat 6.0.6 6.0.6.x
apache / tomcat 6.0.4-alpha 6.0.4-alpha.x
apache / tomcat 6.0.11 6.0.11.x
apache / tomcat 6.0.7 6.0.7.x
apache / tomcat 6.0.4 6.0.4.x
apache / tomcat 6.0.15 6.0.15.x
apache / tomcat 6.0.20 6.0.20.x
apache / tomcat 6.0.9-beta 6.0.9-beta.x
apache / tomcat 6.0.10 6.0.10.x
apache / tomcat 6.0.31 6.0.31.x
apache / tomcat 6.0.29 6.0.29.x
apache / tomcat 6.0.3 6.0.3.x
apache / tomcat 6.0.9 6.0.9.x
apache / tomcat 6.0.1-alpha 6.0.1-alpha.x
apache / tomcat 6.0.7-alpha 6.0.7-alpha.x
apache / tomcat 6.0.24 6.0.24.x
apache / tomcat 6.0.17 6.0.17.x
apache / tomcat 6.0 6.0.x
apache / tomcat 6.0.32 6.0.32.x
apache / tomcat 6.0.28 6.0.28.x
apache / tomcat 6.0.0 6.0.0.x
apache / tomcat 6.0.14 6.0.14.x
apache / tomcat 6.0.6-alpha 6.0.6-alpha.x
apache / tomcat 6.0.1 6.0.1.x
apache / tomcat 6.0.12 6.0.12.x
apache / tomcat 6.0.18 6.0.18.x
apache / tomcat 6.0.2-alpha 6.0.2-alpha.x
apache / tomcat 6.0.5 6.0.5.x
apache / tomcat 6.0.7-beta 6.0.7-beta.x
apache / tomcat 6.0.30 6.0.30.x
apache / tomcat 6.0.2 6.0.2.x
apache / tomcat 6.0.2-beta 6.0.2-beta.x
apache / tomcat 6.0.13 6.0.13.x
apache / tomcat 6.0.8-alpha 6.0.8-alpha.x
apache / tomcat 6.0.26 6.0.26.x
apache / tomcat 6.0.19 6.0.19.x
apache / tomcat 6.0.27 6.0.27.x
apache / tomcat 6.0.35 6.0.35.x
apache / tomcat 6.0.16 6.0.16.x
apache / tomcat 6.0.8 6.0.8.x
apache / tomcat 7.0.2-beta 7.0.2-beta.x
apache / tomcat 7.0.12 7.0.12.x
apache / tomcat 7.0.20 7.0.20.x
apache / tomcat 7.0.8 7.0.8.x
apache / tomcat 7.0.1 7.0.1.x
apache / tomcat 7.0.2 7.0.2.x
apache / tomcat 7.0.5 7.0.5.x
apache / tomcat 7.0.4-beta 7.0.4-beta.x
apache / tomcat 7.0.22 7.0.22.x
apache / tomcat 7.0.28 7.0.28.x
apache / tomcat 7.0.0 7.0.0.x
apache / tomcat 7.0.6 7.0.6.x
apache / tomcat 7.0.18 7.0.18.x
apache / tomcat 7.0.14 7.0.14.x
apache / tomcat 7.0.11 7.0.11.x
apache / tomcat 7.0.23 7.0.23.x
apache / tomcat 7.0.0-beta 7.0.0-beta.x
apache / tomcat 7.0.7 7.0.7.x
apache / tomcat 7.0.13 7.0.13.x
apache / tomcat 7.0.30 7.0.30.x
apache / tomcat 7.0.15 7.0.15.x
apache / tomcat 7.0.19 7.0.19.x
apache / tomcat 7.0.16 7.0.16.x
apache / tomcat 7.0.10 7.0.10.x
apache / tomcat 7.0.25 7.0.25.x
apache / tomcat 7.0.21 7.0.21.x
apache / tomcat 7.0.17 7.0.17.x
apache / tomcat 7.0.9 7.0.9.x
apache / tomcat 7.0.4 7.0.4.x
apache / tomcat 7.0.3 7.0.3.x
Maven icon org.apache.tomcat / tomcat 6.0.0 6.0.36
Maven icon org.apache.tomcat / tomcat 7.0.0 7.0.32