CVE-2016-4993
MEDIUMWildFly <7.0.2 - CRLF Injection
Title source: llmDescription
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
References (11)
Scores
CVSS v3
6.1
EPSS
0.0148
EPSS Percentile
80.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-113
CWE-93
Status
published
Affected Products (4)
redhat/jboss_enterprise_application_platform
< 7.0.1
redhat/jboss_wildfly_application_server
org.wildfly/wildfly-undertow
< 11.0.0.FinalMaven
n/a/n/a
Timeline
Published
Sep 26, 2016
Tracked Since
Feb 18, 2026