Improper access control in Apache Tomcat - CVE-2016-5388
Published: June 22, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable. A remote attacker can redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
Affected software
FlashSystem 900 9840-AE2 and 9843-AE2
FlashSystem 840 9840-AE1 & 9843-AE1
Storage Copy Data Management
Arch Linux
Dell Secure Connect Gateway
tomcat6
tomcat7
tomcat8
IBM Storwize V3500
IBM Storwize V3700
IBM Storwize V5000
IBM Storwize V7000
IBM FlashSystem V9000
How to mitigate CVE-2016-5388
Dell Secure Connect Gateway - update to 5.12.00.10
Storage Copy Data Management - update to 2.2.26.0
tomcat6 - update to 6.0.47-1
tomcat7 - update to 7.0.72-1
IBM Storwize V3500 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3
IBM Storwize V3700 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3
IBM Storwize V5000 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3
IBM Storwize V7000 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3
IBM FlashSystem V9000 - addressed in versions 7.6.1.6, 7.7.0.4, 7.7.1.3
tomcat8 - update to 8.0.37-1
External References
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00025.html
- http://rhn.redhat.com/errata/RHSA-2016-1624.html
- http://rhn.redhat.com/errata/RHSA-2016-2045.html
- http://rhn.redhat.com/errata/RHSA-2016-2046.html
- http://www.kb.cert.org/vuls/id/797896
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html
- http://www.securityfocus.com/bid/91818
- http://www.securitytracker.com/id/1036331
- https://access.redhat.com/errata/RHSA-2016:1635
- https://access.redhat.com/errata/RHSA-2016:1636
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_us
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324759
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
- https://httpoxy.org/
- https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/6b414817c2b0bf351138911c8c922ec5dd577ebc0b9a7f42d705752d@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/r2853582063cfd9e7fbae1e029ae004e6a83482ae9b70a698996353dd@%3Cusers.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rc6b2147532416cc736e68a32678d3947b7053c3085cf43a9874fd102@%3Cusers.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rf21b368769ae70de4dee840a3228721ae442f1d51ad8742003aefe39@%3Cusers.tomcat.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2019/08/msg00015.html
- https://tomcat.apache.org/tomcat-7.0-doc/changelog.html
- https://www.apache.org/security/asf-httpoxy-response.txt
Related Security Bulletins
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in IBM FlashSystem models 840 and 900
- Multiple vulnerabilities in SAN Volume Controller, Storwize family and FlashSystem V9000 products
- Arch Linux update for tomcat8
- Arch Linux update for tomcat7
- Arch Linux update for tomcat6
- Multiple vulnerabilities in IBM Storage Copy Data Management