FlawAtlas
Search the atlas
CVE-2015-5351 High

Apache Tomcat allows remote attackers to bypass a CSRF protection mechanism by using a token

The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mechanism by using a token.

Exploit probability 9.7%
Published May 14, 2022
Required by Not available
Last source change February 18, 2024

02 / AFFECTED SOFTWARE

Affected packages

Maven org.apache.tomcat:tomcat

43 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-w7cg-5969-678w

The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mechanism by using a token.

View original source

05 / REFERENCES

Further evidence