V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2018-1067
DEB
Medium

In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulne…

CVSS
5.4
Medium
EPSS
0.02
p75
Published
2018-01-01
Updated
2018-01-01
Description

In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.

Tags · CWE
Pre-auth
CWE-113
CAPEC-31
CAPEC-34
CAPEC-85
CAPEC-105
Affected products
Eap7-activemq-artemisEap7-activemq-artemisEap7-hibernateEap7-hibernateEap7-infinispanEap7-infinispanEap7-ironjacamarEap7-ironjacamarEap7-jboss-ec2-eapEap7-jboss-ec2-eapEap7-jboss-ejb-clientEap7-jboss-ejb-clientEap7-jboss-jsf-api_2.2_specEap7-jboss-jsf-api_2.2_specEap7-jboss-marshallingEap7-jboss-marshallingEap7-jboss-server-migrationEap7-jboss-server-migrationEap7-jboss-weld-2.2-apiEap7-jboss-weld-2.2-api
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.018 · p75
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-31 · CWE-113
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
eap7-activemq-artemisTracked
eap7-activemq-artemisTracked
eap7-hibernateTracked
eap7-hibernateTracked
eap7-infinispanTracked
eap7-infinispanTracked
eap7-ironjacamarTracked
eap7-ironjacamarTracked
eap7-jboss-ec2-eapTracked
eap7-jboss-ec2-eapTracked
eap7-jboss-ejb-clientTracked
eap7-jboss-ejb-clientTracked
eap7-jboss-jsf-api_2.2_specTracked
eap7-jboss-jsf-api_2.2_specTracked
eap7-jboss-marshallingTracked
eap7-jboss-marshallingTracked
eap7-jboss-server-migrationTracked
eap7-jboss-server-migrationTracked
eap7-jboss-weld-2.2-apiTracked
eap7-jboss-weld-2.2-apiTracked
Showing first 20 of 63
Source databases
DEB
CVE
RED
UBU