Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2016-5387 | First vendor Publication | 2016-07-18 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H | |||
---|---|---|---|
Overall CVSS Score | 8.1 | ||
Base Score | 8.1 | Environmental Score | 8.1 |
impact SubScore | 5.9 | Temporal Score | 8.1 |
Exploitabality Sub Score | 2.2 | ||
Attack Vector | Network | Attack Complexity | High |
Privileges Required | None | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | High | Availability Impact | High |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5387 |
CPE : Common Platform Enumeration
Snort® IPS/IDS
Date | Description |
---|---|
2016-07-28 | HttpOxy CGI application vulnerability potential man-in-the-middle attempt RuleID : 39737-community - Revision : 2 - Type : SERVER-WEBAPP |
2016-08-31 | HttpOxy CGI application vulnerability potential man-in-the-middle attempt RuleID : 39737 - Revision : 2 - Type : SERVER-WEBAPP |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2017-11-03 | Name : The remote host is missing a macOS or Mac OS X security update that fixes mul... File : macosx_SecUpd2017-004.nasl - Type : ACT_GATHER_INFO |
2017-10-03 | Name : The remote host is missing a macOS update that fixes multiple security vulner... File : macos_10_13.nasl - Type : ACT_GATHER_INFO |
2017-07-20 | Name : An enterprise management application installed on the remote host is affected... File : oracle_enterprise_manager_jul_2017_cpu.nasl - Type : ACT_GATHER_INFO |
2017-06-26 | Name : The Tenable SecurityCenter application on the remote host contains a web serv... File : securitycenter_apache_2_4_25.nasl - Type : ACT_GATHER_INFO |
2017-05-01 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2016-1030.nasl - Type : ACT_GATHER_INFO |
2017-03-31 | Name : The remote host is missing a macOS update that fixes multiple security vulner... File : macos_10_12_4.nasl - Type : ACT_GATHER_INFO |
2017-03-14 | Name : An application installed on the remote host is affected by multiple vulnerabi... File : securitycenter_5_4_3_tns_2017_04.nasl - Type : ACT_GATHER_INFO |
2017-01-16 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201701-36.nasl - Type : ACT_GATHER_INFO |
2017-01-12 | Name : The remote web server is affected by multiple vulnerabilities. File : apache_2_4_25.nasl - Type : ACT_GATHER_INFO |
2017-01-12 | Name : The remote web server is affected by multiple vulnerabilities. File : apache_2_2_32.nasl - Type : ACT_GATHER_INFO |
2016-12-27 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2016-358-01.nasl - Type : ACT_GATHER_INFO |
2016-12-21 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_862d6ab3c75e11e69f9820cf30e32f6d.nasl - Type : ACT_GATHER_INFO |
2016-11-09 | Name : The remote web server is affected by multiple vulnerabilities. File : hpsmh_7_6.nasl - Type : ACT_GATHER_INFO |
2016-09-15 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-1851.nasl - Type : ACT_GATHER_INFO |
2016-09-02 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-2090-1.nasl - Type : ACT_GATHER_INFO |
2016-08-26 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-1649.nasl - Type : ACT_GATHER_INFO |
2016-08-26 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-1648.nasl - Type : ACT_GATHER_INFO |
2016-08-22 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-1005.nasl - Type : ACT_GATHER_INFO |
2016-08-19 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-1636.nasl - Type : ACT_GATHER_INFO |
2016-08-19 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-1635.nasl - Type : ACT_GATHER_INFO |
2016-08-09 | Name : The remote Fedora host is missing a security update. File : fedora_2016-683d0b257b.nasl - Type : ACT_GATHER_INFO |
2016-08-09 | Name : The remote Fedora host is missing a security update. File : fedora_2016-a29c65b00f.nasl - Type : ACT_GATHER_INFO |
2016-08-01 | Name : The remote Debian host is missing a security update. File : debian_DLA-568.nasl - Type : ACT_GATHER_INFO |
2016-07-28 | Name : The remote Fedora host is missing a security update. File : fedora_2016-df0726ae26.nasl - Type : ACT_GATHER_INFO |
2016-07-26 | Name : The version of PHP running on the remote web server is affected by multiple v... File : php_7_0_9.nasl - Type : ACT_GATHER_INFO |
2016-07-26 | Name : The version of PHP running on the remote web server is affected by multiple v... File : php_5_6_24.nasl - Type : ACT_GATHER_INFO |
2016-07-26 | Name : The version of PHP running on the remote web server is affected by multiple v... File : php_5_5_38.nasl - Type : ACT_GATHER_INFO |
2016-07-25 | Name : The remote web application is affected by a man-in-the-middle vulnerability. File : http_httpoxy.nasl - Type : ACT_ATTACK |
2016-07-25 | Name : The remote Fedora host is missing a security update. File : fedora_2016-9fd9bfab9e.nasl - Type : ACT_GATHER_INFO |
2016-07-21 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2016-725.nasl - Type : ACT_GATHER_INFO |
2016-07-21 | Name : The remote Debian host is missing a security update. File : debian_DLA-553.nasl - Type : ACT_GATHER_INFO |
2016-07-21 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3623.nasl - Type : ACT_GATHER_INFO |
2016-07-21 | Name : A PHP application running on the remote web server is affected by a man-in-th... File : drupal_8_1_7.nasl - Type : ACT_GATHER_INFO |
2016-07-20 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-880.nasl - Type : ACT_GATHER_INFO |
2016-07-19 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2016-1421.nasl - Type : ACT_GATHER_INFO |
2016-07-19 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2016-1422.nasl - Type : ACT_GATHER_INFO |
2016-07-19 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2016-1421.nasl - Type : ACT_GATHER_INFO |
2016-07-19 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2016-1422.nasl - Type : ACT_GATHER_INFO |
2016-07-19 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-1421.nasl - Type : ACT_GATHER_INFO |
2016-07-19 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-1422.nasl - Type : ACT_GATHER_INFO |
2016-07-19 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20160718_httpd_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2016-07-19 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20160718_httpd_on_SL7_x.nasl - Type : ACT_GATHER_INFO |
2016-07-19 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-3038-1.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 12:57:35 |
|
2024-08-02 12:41:36 |
|
2024-08-02 01:11:55 |
|
2024-02-02 01:40:21 |
|
2024-02-01 12:11:24 |
|
2023-11-07 21:43:48 |
|
2023-09-05 12:38:26 |
|
2023-09-05 01:11:11 |
|
2023-09-02 12:38:16 |
|
2023-09-02 01:11:26 |
|
2023-08-12 12:41:33 |
|
2023-08-12 01:10:54 |
|
2023-08-11 12:36:26 |
|
2023-08-11 01:11:12 |
|
2023-08-06 12:35:13 |
|
2023-08-06 01:10:53 |
|
2023-08-04 12:35:22 |
|
2023-08-04 01:10:57 |
|
2023-07-14 12:35:24 |
|
2023-07-14 01:10:56 |
|
2023-03-29 01:37:10 |
|
2023-03-28 12:11:16 |
|
2022-10-11 12:31:40 |
|
2022-10-11 01:10:56 |
|
2022-10-07 01:29:53 |
|
2022-09-07 21:27:41 |
|
2021-06-25 01:20:21 |
|
2021-06-06 17:23:00 |
|
2021-06-03 13:23:11 |
|
2021-05-05 01:23:03 |
|
2021-05-04 12:53:40 |
|
2021-04-22 02:06:23 |
|
2021-03-30 17:22:50 |
|
2020-10-10 01:15:59 |
|
2020-05-23 02:00:42 |
|
2020-05-23 00:52:14 |
|
2019-08-16 12:04:46 |
|
2018-09-22 12:06:34 |
|
2018-04-16 01:03:48 |
|
2018-03-03 12:04:05 |
|
2018-01-18 21:22:34 |
|
2017-12-09 13:24:14 |
|
2017-11-14 09:23:12 |
|
2017-11-04 13:25:25 |
|
2017-11-03 09:21:16 |
|
2017-10-01 01:01:04 |
|
2017-09-22 13:24:45 |
|
2017-08-25 09:22:57 |
|
2017-08-09 09:23:34 |
|
2017-07-22 12:03:49 |
|
2017-07-21 13:24:50 |
|
2017-07-01 09:23:42 |
|
2017-06-27 13:23:21 |
|
2017-05-02 13:24:37 |
|
2017-04-01 13:25:06 |
|
2017-03-21 09:20:08 |
|
2017-03-15 13:22:41 |
|
2017-02-17 09:23:57 |
|
2017-01-17 13:22:45 |
|
2017-01-13 13:24:47 |
|
2016-12-22 13:22:45 |
|
2016-12-07 00:24:54 |
|
2016-11-29 00:26:28 |
|
2016-11-10 13:24:18 |
|
2016-11-02 21:25:50 |
|
2016-10-29 09:23:24 |
|
2016-10-27 09:24:00 |
|
2016-09-30 01:06:06 |
|
2016-09-28 21:24:34 |
|
2016-09-28 09:23:44 |
|
2016-09-16 13:24:48 |
|
2016-09-03 13:27:33 |
|
2016-08-27 13:26:29 |
|
2016-08-23 13:23:44 |
|
2016-08-20 13:26:23 |
|
2016-08-16 21:25:09 |
|
2016-08-12 09:24:59 |
|
2016-08-10 13:25:32 |
|
2016-08-02 13:21:17 |
|
2016-07-29 13:25:27 |
|
2016-07-26 13:25:55 |
|
2016-07-22 13:38:25 |
|
2016-07-20 01:00:26 |
|
2016-07-19 12:02:29 |
|