CVE-2015-5351: Apache Tomcat
High severity, CVSS 8.8. EPSS: 9.7% chance of exploitation in the next 30 days.
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mechanism by using a token.
Affected products
- Apache Tomcat: version 7.0.0 only; version 7.0.2 only; version 7.0.4 only; version 7.0.5 only; version 7.0.6 only; version 7.0.10 only; …
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
Published 2016-02-25. Last modified 2026-06-17.