cbcvebase.
CVE-2016-5387
published 2016-07-19

CVE-2016-5387: The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in…

PriorityP359high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
55.72%
98.9th percentile
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.

Affected

50 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttp_server2.2.0 – 2.2.31
apachehttp_server2.4.1 – 2.4.23
applemac_os_x<= 10.11.6
applemacos_high_sierra
applemacos_high_sierra_10.13.1_security_update_2017-001_sierra_and_security_update_20
applemacos_sierra_10.12.4_security_update_2017-001_el_capitan_and_security_update_201
appleos_x_server<= 5.1
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianapache2< apache2 2.4.23-2 (bookworm)apache2 2.4.23-2 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
hpsystem_management_homepage<= 7.5.5.0
opensuseleap
opensuseopensuse
oraclecommunications_user_data_repository10.0.0 – 12.4
oracleenterprise_manager_ops_center
oracleenterprise_manager_ops_center
oraclelinux
oraclelinux
oraclelinux
oraclesolaris

Detection & IOCsextracted from sources · hover to see the quote

  • Detect exploitation attempts by inspecting HTTP requests for a crafted 'Proxy' header, which Apache HTTP Server would convert into the HTTP_PROXY environment variable and potentially redirect outbound CGI traffic to an attacker-controlled proxy.
  • Monitor CGI script execution environments for the presence of an HTTP_PROXY environment variable sourced from untrusted client-supplied request headers, which is the core exploitation mechanism of the httpoxy attack class.
  • For mod_fcgid deployments, check whether 'FcgidPassHeader Proxy' is configured, as this directive enables the vulnerability even after Apache HTTPD is patched for CVE-2016-5387.
  • Alert on inbound HTTP requests containing a 'Proxy:' header targeting Apache HTTP Server instances running CGI applications, as this is the attacker-controlled input vector for the httpoxy issue.
  • ·The vulnerability is only exploitable when CGI scripts honour the HTTP_PROXY environment variable; applications not using CGI or not reading HTTP_PROXY are not affected.
  • ·mod_fcgid is only vulnerable if 'FcgidPassHeader Proxy' is explicitly configured; patching Apache HTTPD for CVE-2016-5387 alone is insufficient to protect mod_fcgid when that directive is in use.
  • ·CVE-2016-5387 is formally a mitigation identifier assigned by the Apache vendor, not a traditional vulnerability CVE; the underlying protocol issue stems from RFC 3875 section 4.1.18 compliance.

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_redhat8.8HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.