RHSA-2017:0244Vendor advisory
http://rhn.redhat.com/errata/RHSA-2017-0244.html CVE-2016-6816
HIGH
Improper Input Validation in Apache Tomcat
Record summary
CVE-2016-6816 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.
Description
The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 12, 2023 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Apache TomcatBrowse Apache Software Foundation / Apache Tomcat | CVE List | 9.0.0.M1 to 9.0.0.M11 | affected |
| 8.5.0 to 8.5.6 | affected | ||
| 8.0.0.RC1 to 8.0.38 | affected | ||
| 7.0.0 to 7.0.72 | affected | ||
| 6.0.0 to 6.0.47 | affected | ||
| Earlier, unsupported versions may also be affected. | affected | ||
org.apache.tomcat:tomcat-coyoteBrowse Maven / org.apache.tomcat:tomcat-coyote | GitHub Advisory | 9.0.0.M1 to < 9.0.0.M12 · Fixed in 9.0.0.M12 | affected |
| 8.5.0 to < 8.5.8 · Fixed in 8.5.8 | affected | ||
| 8.0.0RC1 to < 8.0.39 · Fixed in 8.0.39 | affected | ||
| 7.0.0 to < 7.0.73 · Fixed in 7.0.73 | affected | ||
| 6.0.0 to < 6.0.48 · Fixed in 6.0.48 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBApache Tomcat 6/7/8/9 - Information DisclosureExploitDB exploitby justpentestNot analyzed1 file
References
Showing 12 of 61RHSA-2017:0245Vendor advisory
http://rhn.redhat.com/errata/RHSA-2017-0245.html RHSA-2017:0246Vendor advisory
http://rhn.redhat.com/errata/RHSA-2017-0246.html RHSA-2017:0247Vendor advisory
http://rhn.redhat.com/errata/RHSA-2017-0247.html RHSA-2017:0250Vendor advisory
http://rhn.redhat.com/errata/RHSA-2017-0250.html RHSA-2017:0457Vendor advisory
http://rhn.redhat.com/errata/RHSA-2017-0457.html RHSA-2017:0527Vendor advisory
http://rhn.redhat.com/errata/RHSA-2017-0527.html DSA-3738Vendor advisory
http://www.debian.org/security/2016/dsa-3738 oracle.comConfirmation
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html 94461vdb entry
http://www.securityfocus.com/bid/94461 1037332vdb entry
http://www.securitytracker.com/id/1037332 RHSA-2017:0455Vendor advisory
https://access.redhat.com/errata/RHSA-2017:0455