PT-2016-5371 · Apache+1 · Apache Http Server+1

Michal Karm Babacek

·

Published

2016-09-26

·

Updated

2023-02-13

·

CVE-2016-3110

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Web Server version 2.1
Description The issue allows remote attackers to cause a denial of service, resulting in an Apache http server crash. This is achieved by sending an MCMP message that contains a series of = (equals) characters after a legitimate element.
Recommendations For Red Hat JBoss Web Server version 2.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Weakness Enumeration

Related Identifiers

CVE-2016-3110
GHSA-68QQ-3PHH-53J7
RHSA-2016:1648
RHSA-2016:1649
RHSA-2016:2054
RHSA-2016:2055

Affected Products

Apache Http Server
Red Hat Jboss Web Server