CVE-2016-8747: Apache Tomcat

High severity, CVSS 7.5. EPSS: 7.1% chance of exploitation in the next 30 days.

An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.

Affected products

  • Apache Tomcat: from 8.5.7, before 8.5.10 (fixed in 8.5.10); version 9.0.0 only
  • Netapp Oncommand Insight: affected versions not specified
  • Netapp Oncommand Shift: affected versions not specified

Published 2017-03-14. Last modified 2026-06-17.