CVE-2007-4724
Summary
| CVE | CVE-2007-4724 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-09-05 19:17:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-site request forgery (CSRF) vulnerability in cal2.jsp in the calendar examples application in Apache Tomcat 4.1.31 allows remote attackers to add events as arbitrary users via the time and description parameters. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/41029 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| archives.neohapsis.com/archives/bugtraq/2007-09/0040.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| SecurityReason - Apache tomcat calendar example cross site scripting and cross site request forgery vulnerability | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Apache | 2007-09-06 | Mark J Cox | This name is a duplicate of CVE-2006-7196. This issue was fixed in Apache Tomcat 4.1.32 and 5.5.16. |
Legacy QID Mappings
- 995390 Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-g77g-vjjm-x83j)