CVE-2016-5388

Description

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an applications outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an httpoxy issue. NOTE: the vendor states A mitigation is planned for future releases of Tomcat, tracked as CVE-2016-5388; in other words, this is not a CVE ID for a vulnerability.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
36.76

Associated Vulnerability

VulnerabilityOS Platform
Update Tomcat to 9.5.14Windows
Update Tomcat to 9.5.5Windows
Update Tomcat to 9.5.7Windows
Update Tomcat to 9.5.8Windows
Update Tomcat to 9.6.10Windows
Update Tomcat to 9.6.3Windows
Update Tomcat to 9.6.4Windows
Update Tomcat to 9.6.7Windows
Update Tomcat to 9.6.8Windows
Update Tomcat to 2.4.5Windows
Update Tomcat to 3.0.14Windows
Update HP System Management Homepage Detection (x64) 7.5.5.0 to latest versionWindows
Update HP System Management Homepage Detection 7.5.5.0 to latest versionWindows
Vulnerabilities CVE-2016-5388 are fixed in Apache-tomcat-catalina 7.0.72Windows
Vulnerabilities CVE-2016-5388 are fixed in Apache-tomcat-catalina 8.5.5Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.6.5Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.4Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.0.6Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.2Windows
Servlet and JSP engine (USN-3081-1) tomcat8_8.0.32-1ubuntu1.3_all.debLinux
Servlet and JSP engine (USN-3081-1) libtomcat8-java_8.0.32-1ubuntu1.3_all.debLinux
Servlet and JSP engine (USN-3177-1) tomcat6_6.0.35-1ubuntu3.9_all.debLinux
Servlet and JSP engine (USN-3177-1) tomcat7_7.0.52-1ubuntu0.8_all.debLinux
Servlet and JSP engine (USN-3177-1) tomcat8_8.0.32-1ubuntu1.3_all.debLinux
Servlet and JSP engine (USN-3177-1) tomcat8_8.0.37-1ubuntu0.1_all.debLinux
Servlet and JSP engine (USN-3177-1) libtomcat6-java_6.0.35-1ubuntu3.9_all.debLinux
Servlet and JSP engine (USN-3177-1) libtomcat7-java_7.0.52-1ubuntu0.8_all.debLinux
Servlet and JSP engine (USN-3177-1) libtomcat8-java_8.0.32-1ubuntu1.3_all.debLinux
Update Tomcat to 9.5.14 (For Linux)Linux
Update Tomcat to 9.5.5 (For Linux)Linux
Update Tomcat to 9.5.7 (For Linux)Linux
Update Tomcat to 9.5.8 (For Linux)Linux
Update Tomcat to 9.6.10 (For Linux)Linux
Update Tomcat to 9.6.3 (For Linux)Linux
Update Tomcat to 9.6.4 (For Linux)Linux
Update Tomcat to 9.6.7 (For Linux)Linux
Update Tomcat to 9.6.8 (For Linux)Linux
Update Tomcat to 2.4.5 (For Linux)Linux
Update Tomcat to 3.0.14 (For Linux)Linux
Update HP System Management Homepage Detection 7.5.5.0 to latest version (For Ubuntu)Linux
Update HP System Management Homepage Detection 7.5.5.0 to latest version (For Debian)Linux
Update HP System Management Homepage Detection 7.5.5.0 to latest version (For Centos)Linux
Update HP System Management Homepage Detection 7.5.5.0 to latest version (For RedHat)Linux
Update HP System Management Homepage Detection 7.5.5.0 to latest version (For Suse)Linux
Vulnerabilities CVE-2016-5388 are fixed in Apache-tomcat-catalina for Linux 7.0.72Linux
Vulnerabilities CVE-2016-5388 are fixed in Apache-tomcat-catalina for Linux 8.5.5Linux
Multiple Vulnerabilities affected in system_management_homepage 7.2.1NCM
Multiple Vulnerabilities affected in system_management_homepage 7.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.2.6NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.11.197-aNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10.186-cNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10.186-bNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10.186NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.8.179NCM
Multiple Vulnerabilities affected in system_management_homepage 7.1NCM
Multiple Vulnerabilities affected in system_management_homepage 7.0NCM
Multiple Vulnerabilities affected in system_management_homepage 6.3.1NCM
Multiple Vulnerabilities affected in system_management_homepage 6.3.0NCM
Multiple Vulnerabilities affected in system_management_homepage 2.2.8NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.15.210NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.15-210NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.15NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.14.20NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.14NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.12.201NCM
Multiple Vulnerabilities affected in system_management_homepage 7.5.4.3NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.0.64NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.0-68NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.0NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2.77-bNCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2.77NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2-77NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.1.73NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.1-73NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.1NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.4NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.3.132NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.1NCM
Multiple Vulnerabilities affected in system_management_homepage 7.4.0NCM
Multiple Vulnerabilities affected in system_management_homepage 6.2.2.7NCM
Multiple Vulnerabilities affected in system_management_homepage 6.1NCM
Multiple Vulnerabilities affected in system_management_homepage 6.0NCM
Multiple Vulnerabilities affected in system_management_homepage 3.2.7NCM
Multiple Vulnerabilities affected in system_management_homepage 3.2.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.9NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.8NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.7-168NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.7NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.6-156NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.6NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5-146NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.3NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.2-127NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-118NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-109NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-103(a)NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-103NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.1NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.0NCM
Multiple Vulnerabilities affected in system_management_homepage 7.5.3.1NCM
Multiple Vulnerabilities affected in system_management_homepage 6.2.0NCM
Multiple Vulnerabilities affected in system_management_homepage 6.1.0.102NCM
Multiple Vulnerabilities affected in system_management_homepage 6.1.0-103NCM
Multiple Vulnerabilities affected in system_management_homepage 6.0.0.96NCM
Multiple Vulnerabilities affected in system_management_homepage 6.0.0-95NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.12-200NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.12-118NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.11-197NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.11NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10-186NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.9-178NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.8-177NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.7.168NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.6.156NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5.146-bNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5.146NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.4.143NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.4-143NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.2.127NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0.121NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.2.106NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.1.104NCM
Improper Access Control Vulnerability (CVE-2016-5388)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234