Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-5387


The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.


Published

2016-07-19T02:00:19.837

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache http_server ≤ 2.2.31 Yes
Application apache http_server ≤ 2.4.23 Yes
Application hp system_management_homepage ≤ 7.5.5.0 Yes
Application oracle communications_user_data_repository ≤ 12.4 Yes
Application oracle enterprise_manager_ops_center 12.2.2 Yes
Application oracle enterprise_manager_ops_center 12.3.2 Yes
Operating System oracle linux 5 Yes
Operating System oracle linux 6 Yes
Operating System oracle linux 7 Yes
Operating System oracle solaris 11.3 Yes
Operating System fedoraproject fedora 23 Yes
Operating System fedoraproject fedora 24 Yes
Application redhat jboss_web_server 2.1.0 Yes
Operating System redhat enterprise_linux 6.0 No
Operating System redhat enterprise_linux 7.0 No
Application redhat jboss_enterprise_web_server 2.0.0 Yes
Application redhat jboss_enterprise_web_server 3.0.0 Yes
Operating System redhat enterprise_linux 6.0 No
Application redhat jboss_enterprise_web_server 2.0.0 Yes
Application redhat jboss_enterprise_web_server 3.0.0 Yes
Operating System redhat enterprise_linux 7.0 No
Application redhat jboss_core_services 1.0 Yes
Operating System redhat enterprise_linux 6.0 No
Operating System redhat enterprise_linux 7.0 No
Operating System redhat enterprise_linux_desktop 6.0 Yes
Operating System redhat enterprise_linux_desktop 7.0 Yes
Operating System redhat enterprise_linux_eus 7.2 Yes
Operating System redhat enterprise_linux_eus 7.3 Yes
Operating System redhat enterprise_linux_eus 7.4 Yes
Operating System redhat enterprise_linux_eus 7.5 Yes
Operating System redhat enterprise_linux_eus 7.6 Yes
Operating System redhat enterprise_linux_eus 7.7 Yes
Operating System redhat enterprise_linux_server 6.0 Yes
Operating System redhat enterprise_linux_server 7.0 Yes
Operating System redhat enterprise_linux_server_aus 7.2 Yes
Operating System redhat enterprise_linux_server_aus 7.3 Yes
Operating System redhat enterprise_linux_server_aus 7.4 Yes
Operating System redhat enterprise_linux_server_aus 7.6 Yes
Operating System redhat enterprise_linux_server_aus 7.7 Yes
Operating System redhat enterprise_linux_server_tus 7.2 Yes
Operating System redhat enterprise_linux_server_tus 7.3 Yes
Operating System redhat enterprise_linux_server_tus 7.6 Yes
Operating System redhat enterprise_linux_server_tus 7.7 Yes
Operating System redhat enterprise_linux_workstation 6.0 Yes
Operating System redhat enterprise_linux_workstation 7.0 Yes
Operating System debian debian_linux 8.0 Yes
Operating System canonical ubuntu_linux 12.04 Yes
Operating System canonical ubuntu_linux 14.04 Yes
Operating System canonical ubuntu_linux 15.10 Yes
Operating System canonical ubuntu_linux 16.04 Yes
Operating System opensuse leap 42.1 Yes
Operating System opensuse opensuse 13.2 Yes

References