VDB

RHSA-2013%3A0648

RHSA-2013%3A0648 PUBLISHED CVSS 4.300000190734863 MEDIUM

org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.

Risk Scores

CVSS 2.0
4.300000190734863

Affected Products

VendorProductVersions
Red HatRed Hat JBoss Enterprise Application Platform 6.0
Red HatRed Hat JBoss Enterprise Application Platform 6.0

Timeline

  • Mar 14, 2013 CVE Published
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Security Advisory
  • Apr 29, 2026 Security Advisory
  • Apr 29, 2026 Security Advisory
  • Apr 29, 2026 Security Advisory
  • Apr 29, 2026 Security Advisory
  • Jun 27, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›