Improper access control in Apache Tomcat - CVE-2016-5388

 

Improper access control in Apache Tomcat - CVE-2016-5388

Published: June 22, 2022


Vulnerability identifier: #VU64586
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5388
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable. A remote attacker can redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.


Affected software

Apache Tomcat
FlashSystem 900 9840-AE2 and 9843-AE2
FlashSystem 840 9840-AE1 & 9843-AE1
Storage Copy Data Management
Arch Linux
Dell Secure Connect Gateway
tomcat6
tomcat7
tomcat8
IBM Storwize V3500
IBM Storwize V3700
IBM Storwize V5000
IBM Storwize V7000
IBM FlashSystem V9000

How to mitigate CVE-2016-5388

Install updates from vendor's website.

Apache Tomcat - addressed in versions 7.0.70, 8.5.4
Dell Secure Connect Gateway - update to 5.12.00.10
Storage Copy Data Management - update to 2.2.26.0
tomcat6 - update to 6.0.47-1
tomcat7 - update to 7.0.72-1
IBM Storwize V3500 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3
IBM Storwize V3700 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3
IBM Storwize V5000 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3
IBM Storwize V7000 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3
IBM FlashSystem V9000 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3
tomcat8 - update to 8.0.37-1

External References

Related Security Bulletins