Improper input validation in Apache Tomcat - CVE-2016-6816
Published: November 22, 2016 / Updated: September 14, 2018
Vulnerability details
The vulnerability allows a remote attacker to manipulate HTTP responses.
The vulnerability exists due to incorrect parsing of HTTP requests. A remote attacker can send a specially crafted HTTP request containing specially crafted characters and perform XSS attacks, manipulate HTTP responses or obtain potentially sensitive data, belonging to other sessions.
Successful exploitation of the vulnerability may allow an attacker to gain access to potentially sensitive information, but requires presence of a proxy server, which does not block injected characters.
Affected software
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
Ubuntu
FlashSystem 840 9840-AE1 & 9843-AE1
Storage Copy Data Management
EMC Cloud Tiering Appliance
FlashSystem 900 9840-AE2 and 9843-AE2
libservlet2.5-java (Ubuntu package)
tomcat
IBM FlashSystem V9000
IBM SAN Volume Controller
IBM Storwize V7000
IBM Storwize V3500
IBM Storwize V5000
IBM Storwize V3700
How to mitigate CVE-2016-6816
libservlet2.5-java (Ubuntu package) - update to 6.0.45+dfsg-1ubuntu0.1
tomcat - addressed in versions 7.0.73-1.el6, 8.0.39-1.fc23, 8.0.39-1.fc24, 8.0.39-1.fc25
IBM FlashSystem V9000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM SAN Volume Controller - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V7000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3500 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V5000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3700 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
EMC Cloud Tiering Appliance - addressed in versions 13.0.0.2.29, 13.1.0.2.20
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Tomcat
- Amazon Linux AMI update for tomcat6
- Amazon Linux AMI update for tomcat6
- Amazon Linux AMI update for tomcat7
- Amazon Linux AMI update for tomcat8
- Red Hat update for tomcat
- Red Hat update for tomcat6
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance
- Multiple vulnerabilities in IBM FlashSystem models 840 and 900
- Multiple vulnerabilities in SAN Volume Controller, Storwize family and FlashSystem V9000 products
- Ubuntu update for tomcat6
- Fedora 24 update for tomcat
- Fedora 23 update for tomcat
- Fedora 25 update for tomcat
- Fedora EPEL 6 update for tomcat
- Multiple vulnerabilities in IBM Storage Copy Data Management