Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-5388

54
FAUCET Score

CVE-2016-5388, known as "httpoxy," affects Apache Tomcat versions 7.x through 7.0.70 and 8.x through 8.5.4 when the CGI Servlet is enabled, as well as products from HP, Oracle, and Red Hat. This vulnerability allows remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server by injecting a crafted Proxy header into an HTTP request, leveraging the HTTP_PROXY environment variable. The vulnerability carries a CVSSv3 score of 8.1 (High), indicating a critical risk due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. Its EPSS score of 0.094020000 and FAUCET Risk Score of 96/100 further emphasize its significant risk. Despite its high severity, there is no evidence of active exploitation (KEV: No) or publicly available exploit code (Metasploit, Nuclei, ExploitDB: None). However, the vulnerability has garnered significant community attention with 2 mentions and 2 media articles, suggesting awareness within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*
7.2CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
7.2CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

8.1HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
50.90%
Probability of exploitation in next 30 days
EPSS Percentile
98.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.5090 is in the 98th percentile among its peer group of 8,914 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (19)

mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 7.0.72
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 8.5.5
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 6Fixed in: httpd24-0:2.4.6-62.ep7.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 6Fixed in: tomcat7-0:7.0.59-51_patch_01.ep7.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 6Fixed in: tomcat8-0:8.0.18-62_patch_01.ep7.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: tomcat7-0:7.0.59-51_patch_01.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: tomcat8-0:8.0.18-62_patch_01.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: httpd24-0:2.4.6-62.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: tomcat6-0:6.0.24-98.el6_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: tomcat-0:7.0.54-8.el7_2
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: tomcat5
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Web Server 2Fixed in: tomcat8
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Web Server 3Fixed in: tomcat6
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6Fixed in: Tomcat
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Web Server 2Fixed in: tomcat7
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 1Fixed in: tomcat
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 5Fixed in: jbossas

Vendor Advisories (2)

mavenGHSA-v646-rx6w-r3qqhigh

Improper Access Control in Apache Tomcat

May 13, 2022
redhatCVE-2016-5388Moderate

Tomcat: CGI sets environmental variable based on user supplied Proxy request header

Jul 18, 2016

References

lists.opensuse.org / opensuse-updates/2016-09/msg00025.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-1624.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2045.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2046.html
Third Party Advisory
access.redhat.com / errata/RHSA-2016:1635
Third Party Advisory
access.redhat.com / errata/RHSA-2016:1636
Third Party Advisory
h20566.www2.hpe.com / hpsc/doc/public/display
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
httpoxy.org
Third Party Advisory
lists.apache.org / thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E
lists.apache.org / thread.html/6b414817c2b0bf351138911c8c922ec5dd577ebc0b9a7f42d705752d%40%3Cissues.activemq.apache.org%3E
lists.apache.org / thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1%40%3Cissues.activemq.apache.org%3E
lists.apache.org / thread.html/r2853582063cfd9e7fbae1e029ae004e6a83482ae9b70a698996353dd%40%3Cusers.tomcat.apache.org%3E
lists.apache.org / thread.html/rc6b2147532416cc736e68a32678d3947b7053c3085cf43a9874fd102%40%3Cusers.tomcat.apache.org%3E
lists.apache.org / thread.html/rf21b368769ae70de4dee840a3228721ae442f1d51ad8742003aefe39%40%3Cusers.tomcat.apache.org%3E
lists.debian.org / debian-lts-announce/2019/08/msg00015.html
tomcat.apache.org / tomcat-7.0-doc/changelog.html
Release NotesVendor Advisory
apache.org / security/asf-httpoxy-response.txt
Vendor Advisory
kb.cert.org / vuls/id/797896
Third Party AdvisoryUS Government Resource
oracle.com / technetwork/security-advisory/cpujul2017-3236622.html
PatchThird Party Advisory
oracle.com / technetwork/topics/security/linuxbulletinoct2016-3090545.html
Third Party Advisory
securityfocus.com / bid/91818
Third Party AdvisoryVDB Entry
securitytracker.com / id/1036331
Third Party AdvisoryVDB EntryVendor Advisory