Security: Improper handling of path parameters allows bypassing the security constraint
Published Jan 6, 2017
7.5
HIGHCVSS 3.0
EPSS 1.42%
Description
An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "/" to a request, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security constraints. The unexpected presence of path parameters can cause a constraint to be bypassed. Users of Apache Tomcat (all current versions) are not affected by this vulnerability since Tomcat follows the guidance previously provided by the Servlet Expert group and strips path parameters from the value returned by getContextPath(), getServletPath(), and getPathInfo(). Users of other Servlet containers based on Apache Tomcat may or may not be affected depending on whether or not the handling of path parameters has been modified. Users of IBM WebSphere Application Server 8.5.x are known to be affected. Users of other containers that implement the Servlet specification may be affected.
Affected products
No data.
Configuration 1
- 3.2.0
- 3.2.1
- 3.2.2
- 3.2.3
- 3.2.4
- 3.2.5
- 3.2.6
- 3.2.7
- 3.2.8
- 3.2.9
- 4.1.0
- 4.1.1
- 4.1.2
- 4.1.3
- 4.2.0
Configuration 2
- 8.5.0.0
- 8.5.0.1
- 8.5.0.2
- 8.5.5.0
- 8.5.5.1
- 8.5.5.2
- 8.5.5.3
- 8.5.5.4
- 8.5.5.5
- 8.5.5.6
- 8.5.5.7
- 8.5.5.8
- 8.5.5.9
No data.
Red Hat JBoss A-MQ 6.3
n/a
Fixed · RHSA-2017:1832
Red Hat JBoss Fuse 6.3
n/a
Fixed · RHSA-2017:1832
Red Hat Enterprise Virtualization 3
jasperreports-server-pro
Under investigation
Red Hat JBoss Fuse 6
camel
Out of support scope
Red Hat OpenShift Enterprise 2
spring-security-core
Under investigation
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss A-MQ 6.3 | n/a | Fixed | RHSA-2017:1832 |
| Red Hat JBoss Fuse 6.3 | n/a | Fixed | RHSA-2017:1832 |
| Red Hat Enterprise Virtualization 3 | jasperreports-server-pro | Under investigation | n/a |
| Red Hat JBoss Fuse 6 | camel | Out of support scope | n/a |
| Red Hat OpenShift Enterprise 2 | spring-security-core | Under investigation | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Use a Servlet container known not to include path parameters in the return values for getServletPath() and getPathInfo()
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
AV:N/AC:L/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.42% (0.01416) | 71.79th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.40% (0.01404) | 68.95th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.32% (0.00322) | 53.00th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.12% (0.00121) | 47.98th | v3 (v2023.03.01) |
| Jun 15, 2024 | 0.12% (0.00121) | 46.59th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.12% (0.00121) | 44.58th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00954) | 36.37th | v2 (v2022.01.01) |
| Sep 2, 2022 | 0.95% (0.00954) | 34.50th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00954) | 32.50th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.95% (0.00954) | 16.28th | v2 (v2022.01.01) |
References (8)
- http://www.securityfocus.com/bid/95142 vdb-entryx_refsource_BID
- https://access.redhat.com/errata/RHSA-2017:1832 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2016-9879 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1409838 Issue Tracking
- https://github.com/advisories/GHSA-v35c-49j6-q8hq Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-9879
- https://pivotal.io/security/cve-2016-9879 x_refsource_CONFIRMMailing ListVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2016-9879
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/95142 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/errata/RHSA-2017:1832 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2016-9879 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1409838 | Issue Tracking | |
| https://github.com/advisories/GHSA-v35c-49j6-q8hq | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2016-9879 | ||
| https://pivotal.io/security/cve-2016-9879 | x_refsource_CONFIRMMailing ListVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2016-9879 |
Change history (0)
No recorded changes yet.