CVE-2016-5387

Description

The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an applications outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an httpoxy issue. NOTE: the vendor states This mitigation has been assigned the identifier CVE-2016-5387; in other words, this is not a CVE ID for a vulnerability.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
58.301

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.2.31Windows
Update HP System Management Homepage Detection (x64) 7.5.5.0 to latest versionWindows
Update HP System Management Homepage Detection 7.5.5.0 to latest versionWindows
Multiple vulnerabilities fixed in Apache Apache 2.4.25Windows
Multiple vulnerabilities are fixed in Apache 2.4.2Windows
Vulnerabilities CVE-2016-4975,CVE-2016-5387,CVE-2016-8743 are fixed in Apache 2.2.3Windows
Multiple vulnerabilities are fixed in IBM HTTP 7.0.0.43Windows
Vulnerabilities CVE-2016-5387 are fixed in IBM HTTP 9.0.0.1Windows
Multiple vulnerabilities are fixed in IBM HTTP 8.5.5.11Windows
Multiple vulnerabilities are fixed in IBM HTTP 8.0.0.13Windows
Multiple vulnerabilities are fixed in IBM HTTP 8.5.5.7Windows
Multiple vulnerabilities are fixed in IBM HTTP 8.0.0.10Windows
Multiple vulnerabilities are fixed in IBM HTTP 7.0.0.37Windows
Multiple vulnerabilities are fixed in IBM WebSphere 7.0.0.43Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.11Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.0.0.13Windows
Vulnerabilities CVE-2016-5387,CVE-2016-3092,CVE-2016-1182,CVE-2016-1181 are fixed in IBM WebSphere 9.0.0.1Windows
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.6 - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.6 Combo Update - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.5 - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.4 - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.4 Combo Update - Reboot AutomaticallyMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.3Mac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.3 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.2Mac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.2 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS High Sierra 10.13.1Mac
Multiple vulnerabilities are fixed in Security Update 2017-001 macOS High Sierra v10.13.1Mac
Multiple vulnerabilities are fixed in Security Update 2017-001 macOS High Sierra v10.13Mac
Apache HTTP server (USN-1627-1) apache2.2-common_2.2.22-1ubuntu1.11_i386.debLinux
Apache HTTP server (USN-1627-1) apache2.2-common_2.2.22-1ubuntu1.11_amd64.debLinux
Apache HTTP server (USN-3038-1) apache2-bin_2.4.12-2ubuntu2.1_i386.debLinux
Apache HTTP server (USN-3038-1) apache2-bin_2.4.12-2ubuntu2.1_amd64.debLinux
Apache HTTP server (USN-3038-1) apache2-bin_2.4.18-2ubuntu3.1_i386.debLinux
Apache HTTP server (USN-3038-1) apache2-bin_2.4.18-2ubuntu3.1_amd64.debLinux
Apache HTTP server (USN-3038-1) apache2.2-bin_2.2.22-1ubuntu1.11_i386.debLinux
Apache HTTP server (USN-3038-1) apache2.2-bin_2.2.22-1ubuntu1.11_amd64.debLinux
(RHSA-2016:1421) Important: httpd security update httpd-2.2.3-92.el5_11.i386.rpmLinux
(RHSA-2016:1421) Important: httpd security update httpd-2.2.3-92.el5_11.x86_64.rpmLinux
(RHSA-2016:1421) Important: httpd security update httpd-devel-2.2.3-92.el5_11.i386.rpmLinux
(RHSA-2016:1421) Important: httpd security update httpd-devel-2.2.3-92.el5_11.x86_64.rpmLinux
(RHSA-2016:1421) Important: httpd security update httpd-manual-2.2.3-92.el5_11.i386.rpmLinux
(RHSA-2016:1421) Important: httpd security update httpd-manual-2.2.3-92.el5_11.x86_64.rpmLinux
(RHSA-2016:1421) Important: httpd security update mod_ssl-2.2.3-92.el5_11.i386.rpmLinux
(RHSA-2016:1421) Important: httpd security update mod_ssl-2.2.3-92.el5_11.x86_64.rpmLinux
Update Apache to version 2.2.31 (For Linux)Linux
Multiple vulnerabilities fixed in Apache Apache 2.4.25 (For Linux)Linux
Update HP System Management Homepage Detection 7.5.5.0 to latest version (For Ubuntu)Linux
Update HP System Management Homepage Detection 7.5.5.0 to latest version (For Debian)Linux
Update HP System Management Homepage Detection 7.5.5.0 to latest version (For Centos)Linux
Update HP System Management Homepage Detection 7.5.5.0 to latest version (For RedHat)Linux
Update HP System Management Homepage Detection 7.5.5.0 to latest version (For Suse)Linux
Multiple Vulnerabilities affected in system_management_homepage 7.5.3.1NCM
Multiple Vulnerabilities affected in system_management_homepage 6.2.0NCM
Multiple Vulnerabilities affected in system_management_homepage 6.1.0.102NCM
Multiple Vulnerabilities affected in system_management_homepage 6.1.0-103NCM
Multiple Vulnerabilities affected in system_management_homepage 6.0.0.96NCM
Multiple Vulnerabilities affected in system_management_homepage 6.0.0-95NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.12-200NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.12-118NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.11-197NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.11NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10-186NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.9-178NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.8-177NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.7.168NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.6.156NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5.146-bNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5.146NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.4.143NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.4-143NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.2.127NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0.121NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.2.106NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.1.104NCM
Multiple Vulnerabilities affected in system_management_homepage 7.2.1NCM
Multiple Vulnerabilities affected in system_management_homepage 7.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.2.6NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.11.197-aNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10.186-cNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10.186-bNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10.186NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.8.179NCM
Multiple Vulnerabilities affected in system_management_homepage 7.1NCM
Multiple Vulnerabilities affected in system_management_homepage 7.0NCM
Multiple Vulnerabilities affected in system_management_homepage 6.3.1NCM
Multiple Vulnerabilities affected in system_management_homepage 6.3.0NCM
Multiple Vulnerabilities affected in system_management_homepage 2.2.8NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.15.210NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.15-210NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.15NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.14.20NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.14NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.12.201NCM
Multiple Vulnerabilities affected in system_management_homepage 7.5.4.3NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.0.64NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.0-68NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.0NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2.77-bNCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2.77NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2-77NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.1.73NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.1-73NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.1NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.4NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.3.132NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.1NCM
Multiple Vulnerabilities affected in system_management_homepage 7.4.0NCM
Multiple Vulnerabilities affected in system_management_homepage 6.2.2.7NCM
Multiple Vulnerabilities affected in system_management_homepage 6.1NCM
Multiple Vulnerabilities affected in system_management_homepage 6.0NCM
Multiple Vulnerabilities affected in system_management_homepage 3.2.7NCM
Multiple Vulnerabilities affected in system_management_homepage 3.2.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.9NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.8NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.7-168NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.7NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.6-156NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.6NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5-146NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.3NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.2-127NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-118NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-109NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-103(a)NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-103NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.1NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.0NCM
CVE-2016-5387NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601563macOS High Sierra 10.13.6 Combo Update - Reboot Automatically
PATCH-601562macOS High Sierra 10.13.6 - Reboot Automatically
PATCH-601312Security Update 2017-001 macOS High Sierra v10.13.1
PATCH-601345Security Update 2017-001 macOS High Sierra v10.13

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234