CVE-2016-8747: Infoleak
Published Mar 14, 2017
·Updated
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.
Affected Software
16 affected componentsFixes available
maven/org.apache.tomcat:tomcat>=9.0.0.M11<=9.0.0.M15
9.0.0.M16
maven/org.apache.tomcat:tomcat>=8.5.7<=8.5.9
8.5.10
Apache Tomcat=8.5.7
Apache Tomcat=8.5.8
Apache Tomcat=8.5.9
Apache Tomcat=9.0.0-milestone11
Apache Tomcat=9.0.0-milestone13
Apache Tomcat=9.0.0-milestone15
Apache Tomcat=9.0.0-m11
Apache Tomcat=9.0.0-m13
Apache Tomcat=9.0.0-m15
NetApp OnCommand Insight
NetApp Oncommand Shift
Apache Tomcat>=8.5.7<8.5.10
Apache Tomcat=9.0.0-milestone12
Apache Tomcat=9.0.0-milestone14
Remediation
Patch Available
Patch Available
Event History
Mar 14, 2017
CVE Published
via MITRE·09:02 AM
Data Sourced
via MITRE·09:02 AM
DescriptionWeakness
Data Sourced
via NVD·09:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 14, 2022
Advisory Published
via GitHub·01:10 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-8747?
CVE-2016-8747 has a moderate severity level as it allows information disclosure in specific reverse-proxy configurations.
2
How do I fix CVE-2016-8747?
To fix CVE-2016-8747, upgrade to Apache Tomcat version 8.5.10 or 9.0.0.M16.
3
What versions of Apache Tomcat are affected by CVE-2016-8747?
CVE-2016-8747 affects Apache Tomcat versions 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15.
4
What type of vulnerability is CVE-2016-8747?
CVE-2016-8747 is classified as an information disclosure vulnerability.
5
Can CVE-2016-8747 be exploited remotely?
Yes, CVE-2016-8747 can be exploited by remote attackers to read sensitive data associated with different requests.