CVE-2015-5351
Description
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mechanism by using a token.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-5351
Vendor advisory: secalert@redhat.com — http://tomcat.apache.org/security-9.html
Vendor advisory: secalert@redhat.com — http://tomcat.apache.org/security-8.html
Vendor advisory: secalert@redhat.com — http://tomcat.apache.org/security-7.html
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2015-5351.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | 7.0 | affected | |
| debian | 8.0 | affected | |
| ubuntu | 12.04 | affected | |
| ubuntu | 14.04 | affected | |
| ubuntu | 15.10 | affected | |
| ubuntu | 16.04 | affected | |
| debian | bookworm | fixed | 0 |
| debian | bullseye | fixed | 0 |
| debian | forky | fixed | 0 |
| debian | sid | fixed | 0 |
| debian | trixie | fixed | 0 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.tomcat:tomcat | <7.0.68 | 7.0.68 |
| Maven | org.apache.tomcat:tomcat | >=8.0.0,<8.0.31 | 8.0.31 |
| Maven | org.apache.tomcat:tomcat | >=9.0.0.M0,<9.0.0.M2 | 9.0.0.M2 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| apache | tomcat | 7.0.0 | |
| apache | tomcat | 7.0.2 | |
| apache | tomcat | 7.0.4 | |
| apache | tomcat | 7.0.5 | |
| apache | tomcat | 7.0.6 | |
| apache | tomcat | 7.0.10 | |
| apache | tomcat | 7.0.11 | |
| apache | tomcat | 7.0.12 | |
| apache | tomcat | 7.0.14 | |
| apache | tomcat | 7.0.16 | |
| apache | tomcat | 7.0.19 | |
| apache | tomcat | 7.0.20 | |
| apache | tomcat | 7.0.21 | |
| apache | tomcat | 7.0.22 | |
| apache | tomcat | 7.0.23 | |
| apache | tomcat | 7.0.25 | |
| apache | tomcat | 7.0.26 | |
| apache | tomcat | 7.0.27 | |
| apache | tomcat | 7.0.28 | |
| apache | tomcat | 7.0.29 | |
| apache | tomcat | 7.0.30 | |
| apache | tomcat | 7.0.32 | |
| apache | tomcat | 7.0.33 | |
| apache | tomcat | 7.0.34 | |
| apache | tomcat | 7.0.35 | |
| apache | tomcat | 7.0.37 | |
| apache | tomcat | 7.0.39 | |
| apache | tomcat | 7.0.40 | |
| apache | tomcat | 7.0.41 | |
| apache | tomcat | 7.0.42 | |
| apache | tomcat | 7.0.47 | |
| apache | tomcat | 7.0.50 | |
| apache | tomcat | 7.0.52 | |
| apache | tomcat | 7.0.53 | |
| apache | tomcat | 7.0.54 | |
| apache | tomcat | 7.0.55 | |
| apache | tomcat | 7.0.56 | |
| apache | tomcat | 7.0.57 | |
| apache | tomcat | 7.0.59 | |
| apache | tomcat | 7.0.61 | |
| apache | tomcat | 7.0.62 | |
| apache | tomcat | 7.0.63 | |
| apache | tomcat | 7.0.64 | |
| apache | tomcat | 7.0.65 | |
| apache | tomcat | 7.0.67 | |
| apache | tomcat | 8.0.0 | |
| apache | tomcat | 8.0.1 | |
| apache | tomcat | 8.0.3 | |
| apache | tomcat | 8.0.11 | |
| apache | tomcat | 8.0.12 | |
| apache | tomcat | 8.0.14 | |
| apache | tomcat | 8.0.15 | |
| apache | tomcat | 8.0.17 | |
| apache | tomcat | 8.0.18 | |
| apache | tomcat | 8.0.20 | |
| apache | tomcat | 8.0.21 | |
| apache | tomcat | 8.0.22 | |
| apache | tomcat | 8.0.23 | |
| apache | tomcat | 8.0.24 | |
| apache | tomcat | 8.0.26 | |
| apache | tomcat | 8.0.27 | |
| apache | tomcat | 8.0.28 | |
| apache | tomcat | 8.0.29 | |
| apache | tomcat | 8.0.30 | |
| apache | tomcat | 9.0.0 | |
References
- https://www.suse.com/security/cve/CVE-2015-5351.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00069.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00085.html
- http://packetstormsecurity.com/files/135882/Apache-Tomcat-CSRF-Token-Leak.html
- http://rhn.redhat.com/errata/RHSA-2016-1089.html
- http://rhn.redhat.com/errata/RHSA-2016-2599.html
- http://rhn.redhat.com/errata/RHSA-2016-2807.html
- http://rhn.redhat.com/errata/RHSA-2016-2808.html
- http://seclists.org/bugtraq/2016/Feb/148
- http://svn.apache.org/viewvc?view=revision&revision=1720652
- http://svn.apache.org/viewvc?view=revision&revision=1720655
- http://svn.apache.org/viewvc?view=revision&revision=1720658
- http://svn.apache.org/viewvc?view=revision&revision=1720660
- http://svn.apache.org/viewvc?view=revision&revision=1720661
- http://svn.apache.org/viewvc?view=revision&revision=1720663
- http://tomcat.apache.org/security-7.html
- http://tomcat.apache.org/security-8.html
- http://tomcat.apache.org/security-9.html
- http://www.debian.org/security/2016/dsa-3530
- http://www.debian.org/security/2016/dsa-3552
- http://www.debian.org/security/2016/dsa-3609
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
CWEs
CWE-352
Verify integrity in audit chain (admin only). AS-IS.