CVE-2016-5388

Aliases:GHSA-v646-rx6w-r3qq
Advisory lineage Upstream: 0 Downstream: 13
Modified
Published: 19 Jul 2016, 01:00
Last modified:06 Aug 2024, 01:00

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
8.1 HIGH
v3.0 (nvd)
EPSS Score
36.76% HIGH
37% probability -28.68%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Jul 2016, 01:00
Published
Vulnerability first disclosed
06 Aug 2024, 01:00
Last Modified
Vulnerability information updated

Description

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "A mitigation is planned for future releases of Tomcat, tracked as CVE-2016-5388"; in other words, this is not a CVE ID for a vulnerability.

CVSS Metrics

  • v3.0HIGHScore: 8.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 5.1AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 36.76% Percentile: 97%

Techniques & Countermeasures

  • CWE-284Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Affected Systems

  • UnknownTomcat

    ≥ 6.0, ≤ 6.0.45 | ≥ 7.0, ≤ 7.0.70 | ≥ 8.0, ≤ 8.5.4

  • hpsystem_management_homepage

    ≤ 7.5.5.0

  • org.apache.tomcattomcat-catalina

    ≥ 7.0.0, < 7.0.72 | ≥ 8.0.0, < 8.5.5

  • oraclelinux

    6 | 7

  • redhatenterprise_linux_desktop

    7.0 | 6.0

  • redhatenterprise_linux_hpc_node

    7.0 | 6.0

  • redhatenterprise_linux_hpc_node_eus

    7.2

  • redhatenterprise_linux_server

    7.0 | 6.0

  • redhatenterprise_linux_server_aus

    7.2

  • redhatenterprise_linux_server_eus

    7.2

  • redhatenterprise_linux_server_tus

    7.2

  • redhatenterprise_linux_workstation

    7.0 | 6.0

References (46)