Lucene search

K
redhatRedHatRHSA-2013:0267
HistoryFeb 19, 2013 - 8:30 p.m.

(RHSA-2013:0267) Moderate: tomcat7 security update

2013-02-1920:30:19
access.redhat.com
18

0.002 Low

EPSS

Percentile

55.0%

Apache Tomcat is a servlet container.

It was found that sending a request without a session identifier to a
protected resource could bypass the Cross-Site Request Forgery (CSRF)
prevention filter. A remote attacker could use this flaw to perform
CSRF attacks against applications that rely on the CSRF prevention filter
and do not contain internal mitigation for CSRF. (CVE-2012-4431)

Warning: Before applying the update, back up your existing JBoss Enterprise
Web Server installation (including all applications and configuration
files).

All users of JBoss Enterprise Web Server 2.0.0 as provided from the Red Hat
Customer Portal are advised to apply this update.