Cross-site Request Forgery (CSRF) Affecting org.apache.tomcat:tomcat-catalina Open this link in a new tab package, versions [7.0.0,7.0.32)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.Test your applications
11 Aug 2014
19 Dec 2012
org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.