Cyber Resilience

CVE-2016-5387

Redhat Enterprise Linux Eus 7.2 … 7.7

High EPSS
Published
19 July 2016
Modified
06 May 2026
Patch / advisory
CVSS Score v3.1 8.1
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.56 99th percentile
Risk Priority 81 floored blend · peak EPSS

Summary

CVE-2016-5387 is a high-severity an unspecified weakness vulnerability in Redhat Enterprise Linux. Its CVSS base score is 8.1 (High).

Operationally, ranked in the top 1% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP…

more

traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.

CWE(s)

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1190 Exploit Public-Facing Application Initial Accessconfidence: HIGH
HTTP_PROXY environment variable manipulation via crafted Proxy header enables exploitation of public-facing web applications.
T1090 Proxy Command And Controlconfidence: MEDIUM
Forces the vulnerable application to route outbound HTTP traffic through an attacker-controlled proxy.
inferred from description · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2019-0211Same product: Apache Http Server
CVE-2016-5385Same product: Debian Debian Linux
CVE-2019-15605Same product: Debian Debian Linux
CVE-2019-14287Same product: Canonical Ubuntu Linux
CVE-2020-11984Same product: Apache Http Server
CVE-2015-2590Same product: Canonical Ubuntu Linux
CVE-2016-3427Same product: Canonical Ubuntu Linux
CVE-2017-9788Same product: Apache Http Server
CVE-2016-5388Same product: Hp System Management Homepage
CVE-2016-1646Same product: Canonical Ubuntu Linux

Affected Assets

apache
http server
2.2.0 — 2.2.31 · 2.4.1 — 2.4.23
hp
system management homepage
≤ 7.5.5.0
oracle
communications user data repository
10.0.0 — 12.4
oracle
enterprise manager ops center
12.2.2, 12.3.2
oracle
linux
5, 6, 7
oracle
solaris
11.3
fedoraproject
fedora
23, 24
redhat
jboss web server
2.1.0
redhat
jboss enterprise web server
2.0.0, 3.0.0
redhat
jboss core services
1.0
+10 more product configuration(s) — see NVD for full list

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References