Improper input validation in Apache Tomcat - CVE-2016-6816

 

Improper input validation in Apache Tomcat - CVE-2016-6816

Published: November 22, 2016 / Updated: September 14, 2018


Vulnerability identifier: #VU1184
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6816
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to manipulate HTTP responses.

The vulnerability exists due to incorrect parsing of HTTP requests. A remote attacker can send a specially crafted HTTP request containing specially crafted characters and perform XSS attacks, manipulate HTTP responses or obtain potentially sensitive data, belonging to other sessions.

Successful exploitation of the vulnerability may allow an attacker to gain access to potentially sensitive information, but requires presence of a proxy server, which does not block injected characters.


Affected software

Apache Tomcat
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
Ubuntu
FlashSystem 840 9840-AE1 & 9843-AE1
Storage Copy Data Management
EMC Cloud Tiering Appliance
FlashSystem 900 9840-AE2 and 9843-AE2
libservlet2.5-java (Ubuntu package)
tomcat
IBM FlashSystem V9000
IBM SAN Volume Controller
IBM Storwize V7000
IBM Storwize V3500
IBM Storwize V5000
IBM Storwize V3700

How to mitigate CVE-2016-6816

Update to version 6.0.48, 7.0.73, 8.0.39 or 9.0.0.M13

Storage Copy Data Management - update to 2.2.26.0
libservlet2.5-java (Ubuntu package) - update to 6.0.45+dfsg-1ubuntu0.1
tomcat - addressed in versions 7.0.73-1.el6, 8.0.39-1.fc23, 8.0.39-1.fc24, 8.0.39-1.fc25
IBM FlashSystem V9000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM SAN Volume Controller - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V7000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3500 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V5000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3700 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
EMC Cloud Tiering Appliance - addressed in versions 13.0.0.2.29, 13.1.0.2.20

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins