CVE-2016-8743
—CVSS 3.1
7.5 high
EPSS
13%p96
Published
()
Modified
Description
Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution.
- Vendors
- apachenetappdebianredhat
- Products
- http server, clustered data ontap, oncommand unified manager, debian linux, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus, enterprise linux workstation, jboss core services
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.