Description
Important: Bypass of CSRF prevention filter CVE-2012-4431
The CSRF prevention filter could be bypassed if a request was made to a protected resource without a session identifier present in the request.
Affected Apache Tomcat versions (7.0.0 - 7.0.31).
Remediation
Upgrade to the latest version of Apache Tomcat.
References
Related Vulnerabilities
Oracle JRE CVE-2014-0463 Vulnerability (CVE-2014-0463)
MySQL CVE-2018-3054 Vulnerability (CVE-2018-3054)
Oracle Application Server CVE-2007-5519 Vulnerability (CVE-2007-5519)
MySQL CVE-2021-2478 Vulnerability (CVE-2021-2478)
Atlassian Jira Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-6619)