V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2017-12165
DEB
LowConfirmedExploit available

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause pos…

CVSS
2.6
Low
EPSS
0.02
p76
Published
2017-01-01
Updated
2017-01-01
Description

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.

Tags · CWE
CWE-444
CAPEC-33
CAPEC-273
Affected products
Eap7-activemq-artemisEap7-activemq-artemisEap7-activemq-artemisEap7-activemq-artemisEap7-antlrEap7-antlrEap7-apache-commons-beanutilsEap7-apache-commons-beanutilsEap7-apache-commons-cliEap7-apache-commons-cliEap7-apache-commons-ioEap7-apache-commons-ioEap7-apache-cxfEap7-apache-cxfEap7-apache-cxf-xjc-utilsEap7-apache-cxf-xjc-utilsEap7-apache-mime4jEap7-apache-mime4jEap7-artemis-nativeEap7-artemis-native
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: L
Low (L)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.019 · p76
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2017-12165
github-poc · https://github.com/dawetmaster/CVE-2017-12165-undertow-vulnerable
Enterprise
Affected products
ProductVendorStatus
eap7-activemq-artemisTracked
eap7-activemq-artemisTracked
eap7-activemq-artemisTracked
eap7-activemq-artemisTracked
eap7-antlrTracked
eap7-antlrTracked
eap7-apache-commons-beanutilsTracked
eap7-apache-commons-beanutilsTracked
eap7-apache-commons-cliTracked
eap7-apache-commons-cliTracked
eap7-apache-commons-ioTracked
eap7-apache-commons-ioTracked
eap7-apache-cxfTracked
eap7-apache-cxfTracked
eap7-apache-cxf-xjc-utilsTracked
eap7-apache-cxf-xjc-utilsTracked
eap7-apache-mime4jTracked
eap7-apache-mime4jTracked
eap7-artemis-nativeTracked
eap7-artemis-nativeTracked
Showing first 20 of 318
Source databases
DEB
CVE
RED
UBU