CVE-2016-6816

HIGH

Apache Tomcat 6.0.0-6.0.47, 7.0.0-7.0.72, 8.0.0.RC1-8.0.38, 8.5.0-8.5.6, 9.0.0.M1-9.0.0.M11 - HTTP Response Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-6816. PoCs published by justpentest.

AI-analyzed exploit summary This exploit demonstrates a security bypass vulnerability in Apache Tomcat by injecting invalid characters into HTTP requests, potentially leading to cache poisoning, XSS, or information disclosure. The PoC provides specific HTTP GET requests that manipulate the response.

Description

The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.

Exploits (1)

exploitdb WORKING POC
by justpentest · textremotemultiple
https://www.exploit-db.com/exploits/41783

This exploit demonstrates a security bypass vulnerability in Apache Tomcat by injecting invalid characters into HTTP requests, potentially leading to cache poisoning, XSS, or information disclosure. The PoC provides specific HTTP GET requests that manipulate the response.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Apache Tomcat 9.0.0.M1 through 9.0.0.M11, 8.5.0 through 8.5.6, 8.0.0.RC1 through 8.0.38, 7.0.0 through 7.0.72, 6.0.0 through 6.0.47
No auth needed
Prerequisites: Access to the target Apache Tomcat server · Ability to send crafted HTTP requests
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (36)

Core 36
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94461
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3738
Release Notes, Vendor Advisory x_refsource_confirm
https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.73
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0244.html
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:0935
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180607-0001/
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0457.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0246.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037332
Release Notes, Vendor Advisory x_refsource_confirm
https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.8
Release Notes, Vendor Advisory x_refsource_confirm
https://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.48
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:0455
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0527.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0245.html
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:0456
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0247.html
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4557-1/
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0250.html
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/41783/
Release Notes, Vendor Advisory x_refsource_confirm
https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.39
Release Notes, Vendor Advisory x_refsource_confirm
https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.0.M13

Scores

CVSS v3 7.1
EPSS 0.0326
EPSS Percentile 87.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (50)
apache/tomcat 6.0.0
apache/tomcat 6.0.1
apache/tomcat 6.0.2
apache/tomcat 6.0.3
apache/tomcat 6.0.4
apache/tomcat 6.0.5
apache/tomcat 6.0.6
apache/tomcat 6.0.7
apache/tomcat 6.0.8
apache/tomcat 6.0.9
... and 40 more
Published Mar 20, 2017
Tracked Since Feb 18, 2026