7.5

CVE-2016-0736

In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheHTTP Server Version2.4.0
ApacheHTTP Server Version2.4.1
ApacheHTTP Server Version2.4.2
ApacheHTTP Server Version2.4.3
ApacheHTTP Server Version2.4.6
ApacheHTTP Server Version2.4.7
ApacheHTTP Server Version2.4.8
ApacheHTTP Server Version2.4.9
ApacheHTTP Server Version2.4.10
ApacheHTTP Server Version2.4.12
ApacheHTTP Server Version2.4.14
ApacheHTTP Server Version2.4.16
ApacheHTTP Server Version2.4.19
ApacheHTTP Server Version2.4.20
ApacheHTTP Server Version2.4.21
ApacheHTTP Server Version2.4.22
ApacheHTTP Server Version2.4.23
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 31.84% 0.967
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
http://www.securityfocus.com/bid/95078
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1037508
Third Party Advisory
VDB Entry