Apache Tomcat CVE-2012-4431 Cross-Site Request Forgery Vulnerability
BID:56814
Info
Apache Tomcat CVE-2012-4431 Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 56814 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-4431 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2012 12:00AM |
| Updated: | May 23 2017 04:26PM |
| Credit: | The Tomcat security team |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 93.E0.21C Xerox FreeFlow Print Server (FFPS) 90.D3.06 Xerox FreeFlow Print Server (FFPS) 82.D2.24 Xerox FreeFlow Print Server (FFPS) 82.D1.44 Xerox FreeFlow Print Server (FFPS) 82.C5.24 Xerox FreeFlow Print Server (FFPS) 81.D0.73 Xerox FreeFlow Print Server (FFPS) 81.C3.31 Xerox FreeFlow Print Server (FFPS) 73.D4.31B Xerox FreeFlow Print Server (FFPS) 73.D4.31 Xerox FreeFlow Print Server (FFPS) 73.D2.33 VMWare vCenter Server 5.1 Redhat JBoss Portal 6.0.0 Redhat JBoss Operations Network 3.1.2 Redhat JBoss Enterprise Web Server EL6 2.0 Redhat JBoss Enterprise Web Server EL5 2.0 Redhat JBoss Enterprise Application Platform 6 EL6 Redhat JBoss Enterprise Application Platform 6 EL5 Redhat JBoss Data Grid 6.0.1 IBM Rational Policy Tester 8.5 4 IBM Rational Policy Tester 8.5.0.2 IBM Rational Policy Tester 8.5.0.1 IBM Rational Policy Tester 8.5 IBM Rational Policy Tester 8.0 IBM Rational Policy Tester 5.6 IBM Rational AppScan Enterprise 8.6.0.2 IBM Rational AppScan Enterprise 8.6.0.1 IBM Rational AppScan Enterprise 8.6.0.0 IBM Rational AppScan Enterprise 8.6 IBM Rational AppScan Enterprise 8.5.0.1 IBM Rational AppScan Enterprise 8.5 IBM Rational AppScan Enterprise 8.0.1.1 IBM Rational AppScan Enterprise 8.0.1 IBM Rational AppScan Enterprise 8.0.0.1 IBM Rational AppScan Enterprise 8.0.0 IBM Rational AppScan Enterprise 5.6 IBM Rational AppScan Enterprise 5.5.0.2 IBM Rational AppScan Enterprise 5.5 Fix Pack 1 IBM Rational AppScan Enterprise 5.5 HP XP P9000 Performance Advisor 5.4.1 HP Service Manager 9.31 HP Service Manager 9.30 HP HP-UX B.11.31 Gentoo Linux CTERA Networks CTERA Portal 3.1 Avaya Voice Portal 5.1.3 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya Messaging Application Server 5.2.1 Avaya Messaging Application Server 5.0.1 Avaya Messaging Application Server 5.2 Avaya Messaging Application Server 5.0 Avaya Meeting Exchange 5.2 SP2 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 SP2 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IP Office Server Edition 8.1 Avaya IP Office Server Edition 8.0 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Conferencing Standard Edition 6.0.1 Avaya Conferencing Standard Edition 6.0 SP1 Avaya Conferencing Standard Edition 6.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Platform 6.2.1 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.2 SP1 Avaya Aura System Platform 6.2 Avaya Aura System Platform 6.0.3.9.3 Avaya Aura System Platform 6.0.3.8.3 Avaya Aura System Platform 6.0.3.0.3 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.0 Avaya Aura System Manager 6.2.3 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.5 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.5 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.0.1 Avaya Aura Session Manager 6.2.2 Avaya Aura Session Manager 6.2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 Avaya Aura Presence Services 6.1.2 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.1.1 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0.2 Avaya Aura Experience Portal 6.0.1 Avaya Aura Experience Portal 6.0 SP2 Avaya Aura Experience Portal 6.0 SP1 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 7.0 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.2 Avaya Aura Application Enablement Services 6.1.2 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.4 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Avaya Application Server 5300 2.0 Apache Tomcat 7.0.31 Apache Tomcat 7.0.30 Apache Tomcat 7.0.29 Apache Tomcat 7.0.28 Apache Tomcat 7.0.27 Apache Tomcat 7.0.26 Apache Tomcat 7.0.25 Apache Tomcat 7.0.24 Apache Tomcat 7.0.23 Apache Tomcat 7.0.16 Apache Tomcat 7.0.14 Apache Tomcat 7.0.13 Apache Tomcat 7.0.12 Apache Tomcat 7.0.3 Apache Tomcat 7.0.2 Apache Tomcat 7.0.1 Apache Tomcat 7.0 beta Apache Tomcat 7.0 Apache Tomcat 6.0.35 Apache Tomcat 6.0.32 Apache Tomcat 6.0.28 Apache Tomcat 6.0.27 Apache Tomcat 6.0.26 Apache Tomcat 6.0.25 Apache Tomcat 6.0.24 Apache Tomcat 6.0.20 Apache Tomcat 6.0.18 Apache Tomcat 6.0.17 Apache Tomcat 6.0.16 Apache Tomcat 6.0.15 Apache Tomcat 6.0.14 Apache Tomcat 6.0.13 Apache Tomcat 6.0.12 Apache Tomcat 6.0.11 Apache Tomcat 6.0.10 Apache Tomcat 6.0.3 Apache Tomcat 6.0.2 Apache Tomcat 6.0.1 Apache Tomcat 6.0 Apache Tomcat 7.0.22 Apache Tomcat 7.0.21 Apache Tomcat 7.0.20 Apache Tomcat 7.0.19 Apache Tomcat 7.0.18 Apache Tomcat 7.0.11 Apache Tomcat 7.0.10 Apache Tomcat 6.0.33 Apache Tomcat 6.0.32 Apache Tomcat 6.0.31 Apache Tomcat 6.0.30 Apache Tomcat 0 |
| Not Vulnerable: |
VMWare vCenter Server 5.1 Update 1 Redhat JBoss Portal 6.1 Redhat JBoss Operations Network 3.2.0 Redhat JBoss Enterprise Application Platform 6.0.1 Redhat JBoss Data Grid 6.1 IBM Rational Policy Tester 8.5.0.3 IBM Rational AppScan Enterprise 8.7 HP XP P9000 Performance Advisor 5.5.1 HP Service Manager 9.31.2004 p2 CTERA Networks CTERA Portal 3.2.28 CTERA Networks CTERA Portal 3.1.39 Avaya Aura System Manager 6.3 Avaya Aura Session Manager 6.3 Avaya Aura Application Server 5300 SIP Core 3.0 Avaya Aura Application Server 5300 SIP Core 2.0 PB28 Apache Tomcat 7.0.32 Apache Tomcat 6.0.36 |
Discussion
Apache Tomcat CVE-2012-4431 Cross-Site Request Forgery Vulnerability
Apache Tomcat is prone to a cross-site request forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain actions in the context of an authorized user and gain access to the affected application; other attacks are also possible.
The following versions are vulnerable:
Tomcat 7.0.0 through 7.0.31
Tomcat 6.0.0 through 6.0.35
Apache Tomcat is prone to a cross-site request forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain actions in the context of an authorized user and gain access to the affected application; other attacks are also possible.
The following versions are vulnerable:
Tomcat 7.0.0 through 7.0.31
Tomcat 6.0.0 through 6.0.35
Exploit / POC
Apache Tomcat CVE-2012-4431 Cross-Site Request Forgery Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to visit a malicious Web page.
To exploit this issue an attacker must entice an unsuspecting victim to visit a malicious Web page.
Solution / Fix
Apache Tomcat CVE-2012-4431 Cross-Site Request Forgery Vulnerability
Solution:
Vendor fixes are available. Please see the references for more information.
Solution:
Vendor fixes are available. Please see the references for more information.
References
Apache Tomcat CVE-2012-4431 Cross-Site Request Forgery Vulnerability
References:
References:
- Apache Tomcat Homepage (Apache)
- Apache Tomcat Security Updates (Apache )
- CVE-2012-4431 Apache Tomcat Cross-Site Request Forgery Vulnerability (Mark Thomas)
- HPSBMU02873 SSRT101182 rev.1 - HP Service Manager, Apache Tomcat Security Update (HP)
- HPSBUX02866 SSRT101139 rev.1 - HP-UX Running Apache, Remote Denial of Service (D (HP)
- Multiple Tomcat vulnerabilities in Oracle Health Sciences Clinical Development C (Oracle)
- Multiple vulnerabilities in CTERA Portal (SEC Consult Vulnerability Lab)
- Xerox Security Bulletin XRX14-004 (Xerox)
- ASA-2013-042: CVE-2012-4431 Apache Tomcat Bypass of CSRF prevention filter (Avaya)
- HPSBST02955 rev.1 - HP XP P9000 Performance Advisor Software, 3rd party Software (HP)
- Important: JBoss Data Grid 6.1.0 update (Red Hat)
- Important: Red Hat JBoss Portal 6.1.0 update (Red Hat)
- Moderate: jbossweb security update (Red Hat)
- Moderate: tomcat6 security update (Red Hat)
- Moderate: tomcat7 security update (Red Hat)
- Moderate: tomcat7 security update (Red Hat)
- RHSA-2013-1853 Moderate: Red Hat JBoss Operations Network 3.2.0 update (Red Hat)
- Security Advisory Moderate: jbossweb security update (Red Hat)
- Security Bulletin: Multiple vulnerabilities in IBM Rational Policy Tester (IBM)
- Security Bulletin: Multiple vulnerabilities in IBM Security AppScan Enterprise (IBM)
- VMware security updates for vCenter Server (VMware)