CVE Database
/

CVE-2016-5388

Back to search

CVE-2016-5388

Published: Jul 19, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "A mitigation is planned for future releases of Tomcat, tracked as CVE-2016-5388"; in other words, this is not a CVE ID for a vulnerability.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2016:1635
vendor-advisory
x_refsource_REDHAT
VU#797896
third-party-advisory
x_refsource_CERT-VN
RHSA-2016:2045
vendor-advisory
x_refsource_REDHAT
RHSA-2016:2046
vendor-advisory
x_refsource_REDHAT
91818
vdb-entry
x_refsource_BID
openSUSE-SU-2016:2252
vendor-advisory
x_refsource_SUSE
RHSA-2016:1624
vendor-advisory
x_refsource_REDHAT
https://httpoxy.org/
x_refsource_MISC
1036331
vdb-entry
x_refsource_SECTRACK
RHSA-2016:1636
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now