Re: Vulnerability Issue with Apache Tomcat 8.0.15 with CSRF token

2017-01-10 Thread Christopher Schultz
25 > PM To: Tomcat Users List Subject: AW: > Vulnerability Issue with Apache Tomcat 8.0.15 with CSRF token > > Hi Abishek, > >> -Ursprüngliche Nachricht- Von: Kumar, Abhishek (IT >> Information Services ) >> [mailto:abhishek.kum...@originenergy.com.a

RE: Vulnerability Issue with Apache Tomcat 8.0.15 with CSRF token

2017-01-10 Thread Kumar, Abhishek (IT Information Services )
: Vulnerability Issue with Apache Tomcat 8.0.15 with CSRF token Hi Abishek,   > -Ursprüngliche Nachricht- > Von: Kumar, Abhishek (IT Information Services ) > [mailto:abhishek.kum...@originenergy.com.au] > Gesendet: Dienstag, 10. Januar 2017 12:17 > An: users@to

AW: Vulnerability Issue with Apache Tomcat 8.0.15 with CSRF token

2017-01-10 Thread Kreuser, Peter
Hi Abishek,   > -Ursprüngliche Nachricht- > Von: Kumar, Abhishek (IT Information Services ) > [mailto:abhishek.kum...@originenergy.com.au] > Gesendet: Dienstag, 10. Januar 2017 12:17 > An: users@tomcat.apache.org > Betreff: Vulnerability Issue

Vulnerability Issue with Apache Tomcat 8.0.15 with CSRF token

2017-01-10 Thread Kumar, Abhishek (IT Information Services )
Hi, The Apache Tomcat web server running on the Load balancer is affected by an information disclosure vulnerability in the index page of the Manager and Host Manager applications. An unauthenticated attacker can exploit this vulnerability to obtain a valid cross-site request forgery (CSRF) to