CVE-2016-3118: Broadcom API Gateway

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

CRLF injection vulnerability in CA API Gateway (formerly Layer7 API Gateway) 7.1 before 7.1.04, 8.0 through 8.3 before 8.3.01, and 8.4 before 8.4.01 allows remote attackers to have an unspecified impact via unknown vectors.

Affected products

  • Broadcom API Gateway: version 7.1 only; version 8.0 only; version 8.1 only; version 8.2 only; version 8.3 only; version 8.4 only

Published 2016-04-06. Last modified 2026-06-17.