8.1

CVE-2016-5387

The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.  NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheHTTP Server Version >= 2.2.0 <= 2.2.31
ApacheHTTP Server Version >= 2.4.1 <= 2.4.23
HpSystem Management Homepage Version <= 7.5.5.0
OracleCommunications User Data Repository Version >= 10.0.0 <= 12.4
OracleLinux Version5 Update-
OracleLinux Version6 Update-
OracleLinux Version7 Update-
OracleSolaris Version11.3
FedoraprojectFedora Version23
FedoraprojectFedora Version24
RedhatJboss Web Server Version2.1.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
RedhatJboss Enterprise Web Server Version2.0.0
   RedhatEnterprise Linux Version6.0
RedhatJboss Enterprise Web Server Version3.0.0
   RedhatEnterprise Linux Version6.0
RedhatJboss Enterprise Web Server Version2.0.0
   RedhatEnterprise Linux Version7.0
RedhatJboss Enterprise Web Server Version3.0.0
   RedhatEnterprise Linux Version7.0
RedhatJboss Core Services Version1.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
RedhatEnterprise Linux Eus Version7.2
RedhatEnterprise Linux Eus Version7.3
RedhatEnterprise Linux Eus Version7.4
RedhatEnterprise Linux Eus Version7.5
RedhatEnterprise Linux Eus Version7.6
RedhatEnterprise Linux Eus Version7.7
DebianDebian Linux Version8.0
CanonicalUbuntu Linux Version12.04 SwEdition-
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version15.10
CanonicalUbuntu Linux Version16.04 SwEditionesm
OpensuseLeap Version42.1
OpensuseOpensuse Version13.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 77.5% 0.989
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
http://rhn.redhat.com/errata/RHSA-2016-1650.html
Third Party Advisory
Broken Link
http://rhn.redhat.com/errata/RHSA-2016-1624.html
Third Party Advisory
Broken Link
http://www.kb.cert.org/vuls/id/797896
Third Party Advisory
US Government Resource
https://httpoxy.org/
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-1625.html
Third Party Advisory
Broken Link
http://www.securityfocus.com/bid/91816
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1036330
Third Party Advisory
Broken Link
VDB Entry