CVE Database
/

CVE-2016-6816

Back to search

CVE-2016-6816

Published: Mar 20, 2017

Modified: Nov 14, 2024

PUBLISHED

Description

The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.

VendorProductVersions

Apache Software Foundation

Apache Tomcat

affected
9.0.0.M1 to 9.0.0.M11
affected
8.5.0 to 8.5.6
affected
8.0.0.RC1 to 8.0.38
affected
7.0.0 to 7.0.72
affected
6.0.0 to 6.0.47

+1 more versions

References

RHSA-2017:0250
vendor-advisory
x_refsource_REDHAT
41783
exploit
x_refsource_EXPLOIT-DB
94461
vdb-entry
x_refsource_BID
DSA-3738
vendor-advisory
x_refsource_DEBIAN
RHSA-2017:0244
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0935
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0457
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0246
vendor-advisory
x_refsource_REDHAT
1037332
vdb-entry
x_refsource_SECTRACK
RHSA-2017:0455
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0527
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0245
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0456
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0247
vendor-advisory
x_refsource_REDHAT
USN-4557-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now