CVE-2016-8747
published 2017-03-14CVE-2016-8747: An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
7.18%
93.6th percentile
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | >= 8.5.7 < 8.5.10 | 8.5.10 |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request
osv·2022-05-14
CVE-2016-8747 [HIGH] Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request
Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.
GHSA
Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request
ghsa·2022-05-14
CVE-2016-8747 [HIGH] CWE-200 Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request
Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.
Red Hat
tomcat: Information leak between requests on the same connection
vendor_redhat·2017-03-13·CVSS 7.5
CVE-2016-8747 [HIGH] CWE-200 tomcat: Information leak between requests on the same connection
tomcat: Information leak between requests on the same connection
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.
Package: tomcat8 (Red Hat JBoss Fuse 6) - Not affected
Package: tomcat8 (Red Hat JBoss Web Server 3) - Not affected
Apache
Apache tomcat: CVE-2016-8747
vendor_apache·CVSS 7.5
CVE-2016-8747 [HIGH] Apache tomcat: CVE-2016-8747
Apache tomcat: CVE-2016-8747
The refactoring to make wider use of ByteBuffer introduced a regression that could cause information to leak between requests on the same connection. When running behind a reverse proxy, this could result in information leakage between users. All HTTP connector variants are affected but HTTP/2 and AJP are not affected. This was fixed in revision 1774166 . This issue was identified by the Apache Tomcat Security Team on 14 December 2016 and made public on 13 March 2017. Affects: 8.5.7 to 8.5.9 8 December 2016 Fixed in Apache Tomcat 8.5.9 Important: Information Disclosure
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8747 tomcat: Information leak between requests on the same connection
bugzilla·2017-03-14·CVSS 7.5
CVE-2016-8747 [HIGH] CVE-2016-8747 tomcat: Information leak between requests on the same connection
CVE-2016-8747 tomcat: Information leak between requests on the same connection
The refactoring to make wider use of ByteBuffer introduced a regression that could cause information to leak between requests on the same connection. When running behind a reverse proxy, this could result in information leakage between users. All HTTP connector variants are affected but HTTP/2 and AJP are not affected.
Fixed in https://svn.apache.org/viewvc?view=revision&revision=1774166
Affects: 8.5.7 to 8.5.9
Bugzilla
CVE-2015-8747 CVE-2015-8748 radicale: Multiple security issues fixed in 1.1
bugzilla·2016-01-05·CVSS 10.0
CVE-2015-8747 [CRITICAL] CVE-2015-8747 CVE-2015-8748 radicale: Multiple security issues fixed in 1.1
CVE-2015-8747 CVE-2015-8748 radicale: Multiple security issues fixed in 1.1
Multiple security fixes related mmostly to improved input sanitization appeared in release of radicale 1.1:
* Improve the regex used for well-known URIs
* Prevent regex injection in rights management
* Prevent crafted HTTP request from calling arbitrary functions
* Improve URI sanitation and conversion to filesystem path
* Decouple the daemon from its parent environment
Upstream patches:
https://github.com/Kozea/Radicale/pull/343/commits
CVE request:
http://seclists.org/oss-sec/2016/q1/22
Discussion:
Created radicale tracking bugs for this issue:
Affects: fedora-all [bug 1295837]
---
Issues stated in changelog can be overlapping, MITRE grouped these issues into two and assigned CVEs:
CVE-2015-8747 - Th
http://svn.apache.org/viewvc?view=revision&revision=1774161http://svn.apache.org/viewvc?view=revision&revision=1774166http://tomcat.apache.org/security-8.htmlhttp://tomcat.apache.org/security-9.htmlhttp://www.securityfocus.com/bid/96895https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20180614-0002/http://svn.apache.org/viewvc?view=revision&revision=1774161http://svn.apache.org/viewvc?view=revision&revision=1774166http://tomcat.apache.org/security-8.htmlhttp://tomcat.apache.org/security-9.htmlhttp://www.securityfocus.com/bid/96895https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20180614-0002/
2017-03-14
Published