---
title: "CVE-2016-4993\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2016-4993?format=md
keywords: index, follow
---

# CVE-2016-4993

Publication date 26 September 2016

Last updated 26 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.1 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2016-4993?format=md#impact-score)

Toggle side navigation

## Description

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0,
as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before
7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct
HTTP response splitting attacks via unspecified vectors.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| undertow | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Needs evaluation |
| 23.10 mantic | Not in release |
| 23.04 lunar | Not in release |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Vulnerable |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.1 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Changed |
  | Confidentiality impact | Low |
  | Integrity impact | Low |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.1 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4993)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2016-4993)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2016-4993)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2016-4993)

### Other references

* <https://issues.jboss.org/browse/UNDERTOW-827>
* <https://www.cve.org/CVERecord?id=CVE-2016-4993>
