Record summary

CVE-2016-6816 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.

Description

The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 12, 2023 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List9.0.0.M1 to 9.0.0.M11affected
8.5.0 to 8.5.6affected
8.0.0.RC1 to 8.0.38affected
7.0.0 to 7.0.72affected
6.0.0 to 6.0.47affected
Earlier, unsupported versions may also be affected.affected

org.apache.tomcat:tomcat-coyote

Browse Maven / org.apache.tomcat:tomcat-coyote
GitHub Advisory9.0.0.M1 to < 9.0.0.M12 · Fixed in 9.0.0.M12affected
8.5.0 to < 8.5.8 · Fixed in 8.5.8affected
8.0.0RC1 to < 8.0.39 · Fixed in 8.0.39affected
7.0.0 to < 7.0.73 · Fixed in 7.0.73affected
6.0.0 to < 6.0.48 · Fixed in 6.0.48affected

Proofs of concept

1

Catalogued exploits

ExploitDBApache Tomcat 6/7/8/9 - Information DisclosureExploitDB exploitby justpentestNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 61