Lucene search

K
cve[email protected]CVE-2016-6816
HistoryMar 20, 2017 - 6:59 p.m.

CVE-2016-6816

2017-03-2018:59:00
CWE-20
web.nvd.nist.gov
238
4
cve-2016-6816
apache tomcat
http request parsing
data injection
xss attack
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

7.9 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.1%

The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.

Affected configurations

Vulners
NVD
Node
apachetomcatRange9.0.0.M19.0.0.M11
OR
apachetomcatRange8.5.08.5.6
OR
apachetomcatRange8.0.0.RC18.0.38
OR
apachetomcatRange7.0.07.0.72
OR
apachetomcatRange6.0.06.0.47

CNA Affected

[
  {
    "product": "Apache Tomcat",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "9.0.0.M1 to 9.0.0.M11"
      },
      {
        "status": "affected",
        "version": "8.5.0 to 8.5.6"
      },
      {
        "status": "affected",
        "version": "8.0.0.RC1 to 8.0.38"
      },
      {
        "status": "affected",
        "version": "7.0.0 to 7.0.72"
      },
      {
        "status": "affected",
        "version": "6.0.0 to 6.0.47"
      },
      {
        "status": "affected",
        "version": "Earlier, unsupported versions may also be affected."
      }
    ]
  }
]

References

Social References

More

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

7.9 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.1%