CVE-2016-5388, known as "httpoxy," affects Apache Tomcat versions 7.x through 7.0.70 and 8.x through 8.5.4 when the CGI Servlet is enabled, as well as products from HP, Oracle, and Red Hat. This vulnerability allows remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server by injecting a crafted Proxy header into an HTTP request, leveraging the HTTP_PROXY environment variable. The vulnerability carries a CVSSv3 score of 8.1 (High), indicating a critical risk due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. Its EPSS score of 0.094020000 and FAUCET Risk Score of 96/100 further emphasize its significant risk. Despite its high severity, there is no evidence of active exploitation (KEV: No) or publicly available exploit code (Metasploit, Nuclei, ExploitDB: None). However, the vulnerability has garnered significant community attention with 2 mentions and 2 media articles, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:* | ||
7.2CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* | ||
7.2CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.