CVE-2015-5351
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, ...
Description
Apache Tomcat allows remote attackers to bypass a CSRF protection mechanism by using a token
In plain language
AI Worth attentionIf you run Apache Tomcat with the Manager or Host Manager apps on an affected version, an attacker can bypass CSRF protection and trick your server into performing dangerous actions—this is a real risk if those apps are reachable and enabled.
CVE-2015-5351 is a CSRF protection bypass in Apache Tomcat’s (1) Manager and (2) Host Manager web applications, where Tomcat can establish sessions and issue CSRF tokens for arbitrary new requests, enabling malicious actions to proceed without valid CSRF protection.
What to do now
- Check whether your Apache Tomcat version is 7.x < 7.0.68, 8.x < 8.0.31, or 9.x < 9.0.0.M2.
- Check whether the Tomcat Manager and/or Host Manager applications are enabled and publicly reachable (for example, accessible from the internet via a browser).
- Upgrade Apache Tomcat to 7.0.68 or newer, or 8.0.31 or newer, or 9.0.0.M2+ (prefer 9.0.0.M3+), so the Manager/Host Manager CSRF behavior is corrected.
- After upgrading, verify that Manager/Host Manager are either disabled or protected so they are not reachable from the internet unless absolutely required.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2015-5351 and every CVE in our database. Create a free account — no credit card required.
Create Free Account