CVE-2016-4993

MEDIUM

WildFly <7.0.2 - CRLF Injection

Title source: llm

Description

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

Scores

CVSS v3 6.1
EPSS 0.0148
EPSS Percentile 80.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-113 CWE-93
Status published

Affected Products (4)

redhat/jboss_enterprise_application_platform < 7.0.1
redhat/jboss_wildfly_application_server
org.wildfly/wildfly-undertow < 11.0.0.FinalMaven
n/a/n/a

Timeline

Published Sep 26, 2016
Tracked Since Feb 18, 2026