The CSRF prevention filter could be bypassed if a request was made to a protected resource without a session identifier present in the request. Tomcat versions 6.0.0 through 6.0.35 and 7.0.0 through 7.0.31 are affected.
74e285db6d16f94ed3552ccea4024d4d096965cbcd236bc2ba5d83beab7e0fda