GHSA-fjwp-r6fm-q6qw · Severity: high · Ecosystem: maven — Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.
Conclusion & alert: CVE-2016-8747 is rated High Risk (66.9/100): CVSS High severity, with high exploitation likelihood (EPSS 7.18%, 93th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +4.23% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.94% | 7.18% | +4.23% |
| 2 | 2026-04-17 | 3.15% | 2.94% | -0.20% |
| 3 | 2026-03-28 | — | 3.15% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-fjwp-r6fm-q6qw · Severity: high · Ecosystem: maven — Apache Tomcat allows remote attackers to read data that was intended to be associated with a different request
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2016-8747 |
suse
|
medium | CVE-2016-8747 severity moderate: SUSE including 12 source package names (tomcat, tomcat-admin-webapps, …), 27 product×package rows across 3 product lines (SUSE Linux Enterprise Server 12 SP1, SUSE Linux Enterprise Server 12 SP2, SUSE Linux Enterprise Server 12-LTSS): Known Not Affected 27. | https://www.suse.com/security/cve/CVE-2016-8747/ |
ubuntu
|
medium | CVE-2016-8747 medium priority: Ubuntu including 1 source packages (tomcat8), 5 status rows across 5 suites (precise, trusty, upstream, xenial, yakkety): DNE 2, not-affected 2, released 1. | https://ubuntu.com/security/CVE-2016-8747 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| netapp | oncommand_insight | — | cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* |
| netapp | oncommand_shift | — | cpe:2.3:a:netapp:oncommand_shift:-:*:*:*:*:*:*:* |
| apache | tomcat | >= 8.5.7, < 8.5.10 | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
| apache | tomcat | 9.0.0 | cpe:2.3:a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:* |
| apache | tomcat | 9.0.0 | cpe:2.3:a:apache:tomcat:9.0.0:milestone12:*:*:*:*:*:* |
| apache | tomcat | 9.0.0 | cpe:2.3:a:apache:tomcat:9.0.0:milestone13:*:*:*:*:*:* |
| apache | tomcat | 9.0.0 | cpe:2.3:a:apache:tomcat:9.0.0:milestone14:*:*:*:*:*:* |
| apache | tomcat | 9.0.0 | cpe:2.3:a:apache:tomcat:9.0.0:milestone15:*:*:*:*:*:* |