8.1

CVE-2016-5388

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "A mitigation is planned for future releases of Tomcat, tracked as CVE-2016-5388"; in other words, this is not a CVE ID for a vulnerability.

Data is provided by the National Vulnerability Database (NVD)
HpSystem Management Homepage Version <= 7.5.5.0
OracleLinux Version6
OracleLinux Version7
ApacheTomcat Version >= 6.0 <= 6.0.45
ApacheTomcat Version >= 7.0 <= 7.0.70
ApacheTomcat Version >= 8.0 <= 8.5.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 69.06% 0.986
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

http://www.kb.cert.org/vuls/id/797896
Third Party Advisory
US Government Resource
https://httpoxy.org/
Third Party Advisory
http://www.securityfocus.com/bid/91818
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1036331
Third Party Advisory
Vendor Advisory
VDB Entry