CVE-2015-5351
Summary
| CVE | CVE-2015-5351 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-02-25 01:59:03 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mechanism by using a token. |
Risk And Classification
Primary CVSS: v3.0 8.8 HIGH from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Problem Types: CWE-352 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 8.8 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Tomcat | 7.0.0 | beta | All | All |
| Application | Apache | Tomcat | 7.0.10 | All | All | All |
| Application | Apache | Tomcat | 7.0.11 | All | All | All |
| Application | Apache | Tomcat | 7.0.12 | All | All | All |
| Application | Apache | Tomcat | 7.0.14 | All | All | All |
| Application | Apache | Tomcat | 7.0.16 | All | All | All |
| Application | Apache | Tomcat | 7.0.19 | All | All | All |
| Application | Apache | Tomcat | 7.0.2 | beta | All | All |
| Application | Apache | Tomcat | 7.0.20 | All | All | All |
| Application | Apache | Tomcat | 7.0.21 | All | All | All |
| Application | Apache | Tomcat | 7.0.22 | All | All | All |
| Application | Apache | Tomcat | 7.0.23 | All | All | All |
| Application | Apache | Tomcat | 7.0.25 | All | All | All |
| Application | Apache | Tomcat | 7.0.26 | All | All | All |
| Application | Apache | Tomcat | 7.0.27 | All | All | All |
| Application | Apache | Tomcat | 7.0.28 | All | All | All |
| Application | Apache | Tomcat | 7.0.29 | All | All | All |
| Application | Apache | Tomcat | 7.0.30 | All | All | All |
| Application | Apache | Tomcat | 7.0.32 | All | All | All |
| Application | Apache | Tomcat | 7.0.33 | All | All | All |
| Application | Apache | Tomcat | 7.0.34 | All | All | All |
| Application | Apache | Tomcat | 7.0.35 | All | All | All |
| Application | Apache | Tomcat | 7.0.37 | All | All | All |
| Application | Apache | Tomcat | 7.0.39 | All | All | All |
| Application | Apache | Tomcat | 7.0.4 | beta | All | All |
| Application | Apache | Tomcat | 7.0.40 | All | All | All |
| Application | Apache | Tomcat | 7.0.41 | All | All | All |
| Application | Apache | Tomcat | 7.0.42 | All | All | All |
| Application | Apache | Tomcat | 7.0.47 | All | All | All |
| Application | Apache | Tomcat | 7.0.5 | beta | All | All |
| Application | Apache | Tomcat | 7.0.50 | All | All | All |
| Application | Apache | Tomcat | 7.0.52 | All | All | All |
| Application | Apache | Tomcat | 7.0.53 | All | All | All |
| Application | Apache | Tomcat | 7.0.54 | All | All | All |
| Application | Apache | Tomcat | 7.0.55 | All | All | All |
| Application | Apache | Tomcat | 7.0.56 | All | All | All |
| Application | Apache | Tomcat | 7.0.57 | All | All | All |
| Application | Apache | Tomcat | 7.0.59 | All | All | All |
| Application | Apache | Tomcat | 7.0.6 | All | All | All |
| Application | Apache | Tomcat | 7.0.61 | All | All | All |
| Application | Apache | Tomcat | 7.0.62 | All | All | All |
| Application | Apache | Tomcat | 7.0.63 | All | All | All |
| Application | Apache | Tomcat | 7.0.64 | All | All | All |
| Application | Apache | Tomcat | 7.0.65 | All | All | All |
| Application | Apache | Tomcat | 7.0.67 | All | All | All |
| Application | Apache | Tomcat | 8.0.0 | rc1 | All | All |
| Application | Apache | Tomcat | 8.0.0 | rc10 | All | All |
| Application | Apache | Tomcat | 8.0.0 | rc3 | All | All |
| Application | Apache | Tomcat | 8.0.0 | rc5 | All | All |
| Application | Apache | Tomcat | 8.0.1 | All | All | All |
| Application | Apache | Tomcat | 8.0.11 | All | All | All |
| Application | Apache | Tomcat | 8.0.12 | All | All | All |
| Application | Apache | Tomcat | 8.0.14 | All | All | All |
| Application | Apache | Tomcat | 8.0.15 | All | All | All |
| Application | Apache | Tomcat | 8.0.17 | All | All | All |
| Application | Apache | Tomcat | 8.0.18 | All | All | All |
| Application | Apache | Tomcat | 8.0.20 | All | All | All |
| Application | Apache | Tomcat | 8.0.21 | All | All | All |
| Application | Apache | Tomcat | 8.0.22 | All | All | All |
| Application | Apache | Tomcat | 8.0.23 | All | All | All |
| Application | Apache | Tomcat | 8.0.24 | All | All | All |
| Application | Apache | Tomcat | 8.0.26 | All | All | All |
| Application | Apache | Tomcat | 8.0.27 | All | All | All |
| Application | Apache | Tomcat | 8.0.28 | All | All | All |
| Application | Apache | Tomcat | 8.0.29 | All | All | All |
| Application | Apache | Tomcat | 8.0.3 | All | All | All |
| Application | Apache | Tomcat | 8.0.30 | All | All | All |
| Application | Apache | Tomcat | 9.0.0 | milestone1 | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 15.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Document Display | HPE Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20566.www2.hpe.com | |
| [Apache-SVN] Revision 1720658 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| [Apache-SVN] Revision 1720660 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| [Apache-SVN] Revision 1720661 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| [Apache-SVN] Revision 1720663 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| USN-3024-1: Tomcat vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Oracle Critical Patch Update - October 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Debian -- Security Information -- DSA-3609-1 tomcat8 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Apache Tomcat® - Apache Tomcat 8 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Vendor Advisory |
| Apache Tomcat® - Apache Tomcat 7 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Vendor Advisory |
| Debian -- Security Information -- DSA-3552-1 tomcat7 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Bugtraq: [SECURITY] CVE-2015-5351 Apache Tomcat CSRF token leak | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| rhn.redhat.com/errata/RHSA-2016-1089.html | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [security-announce] SUSE-SU-2016:0822-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| February 2016 Apache Tomcat Vulnerabilities in NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | |
| [Apache-SVN] Revision 1720655 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| Oracle Critical Patch Update - October 2017 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| [security-announce] openSUSE-SU-2016:0865-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Apache Tomcat: Multiple vulnerabilities (GLSA 201705-09) — Gentoo Security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Document Display | HPE Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20566.www2.hpe.com | |
| Broadcom Support Portal | af854a3a-2127-422b-91ae-364da2661108 | bto.bluecoat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Debian -- Security Information -- DSA-3530-1 tomcat6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Apache Tomcat CVE-2015-5351 Cross Site Request Forgery Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Apache Tomcat CSRF Token Leak ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| CPU July 2018 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| [Apache-SVN] Revision 1720652 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| Apache Tomcat - Apache Tomcat 8 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Vendor Advisory |
| [security-announce] SUSE-SU-2016:0769-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| MySupport - Micro Focus Software Support | af854a3a-2127-422b-91ae-364da2661108 | softwaresupport.hpe.com | |
| Apache Tomcat Bugs Let Remote Users Bypass Security Restrictions, Hijack Sessions, and Obtain Potentially Sensitive Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 996880 Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-w7cg-5969-678w)