CVE-2016-4993
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting…
Does this matter?
Lower severity and a low EPSS score (2.56%). Track it; it rarely justifies an emergency change on its own.
Description
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.56% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-93, CWE-113
- Affected
- redhat/jboss enterprise application platform · redhat/jboss wildfly application server
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2016-1838.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1839.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1840.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1841.htmlThird Party Advisory
- http://www.securityfocus.com/bid/92894
- http://www.securitytracker.com/id/1036758Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3454
- https://access.redhat.com/errata/RHSA-2017:3455
- https://access.redhat.com/errata/RHSA-2017:3456
- https://access.redhat.com/errata/RHSA-2017:3458
- https://bugzilla.redhat.com/show_bug.cgi?id=1344321Issue Tracking, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1838.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1839.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1840.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1841.htmlThird Party Advisory
- http://www.securityfocus.com/bid/92894
- http://www.securitytracker.com/id/1036758Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3454
- https://access.redhat.com/errata/RHSA-2017:3455
- https://access.redhat.com/errata/RHSA-2017:3456
- https://access.redhat.com/errata/RHSA-2017:3458
- https://bugzilla.redhat.com/show_bug.cgi?id=1344321Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.