CVE Vulnerabilities

CVE-2016-5387

Published: Jul 19, 2016 | Modified: Apr 12, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
5 IMPORTANT
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
5 IMPORTANT
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an applications outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an httpoxy issue. NOTE: the vendor states This mitigation has been assigned the identifier CVE-2016-5387; in other words, this is not a CVE ID for a vulnerability.

Affected Software

NameVendorStart VersionEnd Version
Http_serverApache2.2.0 (including)2.2.31 (including)
Http_serverApache2.4.1 (including)2.4.23 (including)
JBoss Core Services on RHEL 6RedHatjbcs-httpd24-httpd-0:2.4.6-77.SP1.jbcs.el6*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-httpd-0:2.4.6-77.SP1.jbcs.el7*
Red Hat Enterprise Linux 5RedHathttpd-0:2.2.3-92.el5_11*
Red Hat Enterprise Linux 6RedHathttpd-0:2.2.15-54.el6_8*
Red Hat Enterprise Linux 7RedHathttpd-0:2.4.6-40.el7_2.4*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHathttpd-0:2.2.26-54.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatjbcs-httpd24-0:1-3.jbcs.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatjbcs-httpd24-openssl-1:1.0.2h-4.jbcs.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatmod_cluster-0:1.2.13-1.Final_redhat_1.1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatmod_cluster-native-0:1.2.13-3.Final_redhat_2.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatmod_jk-0:1.2.41-2.redhat_3.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHattomcat-native-0:1.1.34-5.redhat_1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHathttpd22-0:2.2.26-56.ep6.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHatjbcs-httpd24-0:1-3.jbcs.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHatjbcs-httpd24-openssl-1:1.0.2h-4.jbcs.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHatmod_cluster-0:1.2.13-1.Final_redhat_1.1.ep6.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHatmod_cluster-native-0:1.2.13-3.Final_redhat_2.ep6.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHatmod_jk-0:1.2.41-2.redhat_3.ep6.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHattomcat-native-0:1.1.34-5.redhat_1.ep6.el7*
Red Hat JBoss Web Server 2.1RedHat*
Red Hat JBoss Web Server 3.0RedHat*
Red Hat JBoss Web Server 3 for RHEL 6RedHathttpd24-0:2.4.6-62.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 6RedHattomcat7-0:7.0.59-51_patch_01.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 6RedHattomcat8-0:8.0.18-62_patch_01.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 7RedHathttpd24-0:2.4.6-62.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHattomcat7-0:7.0.59-51_patch_01.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHattomcat8-0:8.0.18-62_patch_01.ep7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHathttpd24-httpd-0:2.4.18-11.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHathttpd24-httpd-0:2.4.18-11.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHathttpd24-httpd-0:2.4.18-11.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHathttpd24-httpd-0:2.4.18-11.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHathttpd24-httpd-0:2.4.18-11.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHathttpd24-httpd-0:2.4.18-11.el7*
Text-Only JBCSRedHat*
Apache2Ubuntudevel*
Apache2Ubuntuesm-infra-legacy/trusty*
Apache2Ubuntuesm-infra/xenial*
Apache2Ubuntuprecise*
Apache2Ubuntutrusty*
Apache2Ubuntutrusty/esm*
Apache2Ubuntuwily*
Apache2Ubuntuxenial*

References