ISOMAN

CVE

CVE-2015-5351

The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mechanism by using a token.

Severity
HIGH
CVSS
8.8
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00047.html
  2. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00069.html
  3. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00085.html
  4. http://packetstormsecurity.com/files/135882/Apache-Tomcat-CSRF-Token-Leak.html
  5. http://rhn.redhat.com/errata/RHSA-2016-1089.html
  6. http://rhn.redhat.com/errata/RHSA-2016-2599.html
  7. http://rhn.redhat.com/errata/RHSA-2016-2807.html
  8. http://rhn.redhat.com/errata/RHSA-2016-2808.html
  9. http://seclists.org/bugtraq/2016/Feb/148
  10. http://svn.apache.org/viewvc?view=revision&revision=1720652
  11. http://svn.apache.org/viewvc?view=revision&revision=1720655
  12. http://svn.apache.org/viewvc?view=revision&revision=1720658
  13. http://svn.apache.org/viewvc?view=revision&revision=1720660
  14. http://svn.apache.org/viewvc?view=revision&revision=1720661
  15. http://svn.apache.org/viewvc?view=revision&revision=1720663
  16. http://tomcat.apache.org/security-7.html
  17. http://tomcat.apache.org/security-8.html
  18. http://tomcat.apache.org/security-9.html
  19. http://www.debian.org/security/2016/dsa-3530
  20. http://www.debian.org/security/2016/dsa-3552