Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13524
HistoryMar 25, 2019 - 8:40 a.m.

Cross-site Request Forgery (CSRF)

2019-03-2508:40:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.001 Low

EPSS

Percentile

30.4%

Apache Tomcat is vulnerable to cross-site request forgery (CSRF). The authenticity of requests are not verified on the server, which allows a remote attacker to perform unauthorized actions on the application by tricking a user into visiting a malicious site that submits unwanted request to the application on behalf of the user.

CPENameOperatorVersion
catalinale5.5.23