I am not sure if this issue belongs to spring security but the stack trace shows a lot of spring security related stuff: Sep 15, 2013 7:20:26 PM org.apache.catalina.core.StandardWrapperValve invoke ...
Randomly seeing the below exception in Prod environments without the sessions getting expired also. Users are getting access denied pages in the middle of the flow and logs show below exception.