peter bassill · operator
$ cve CVE-2016-8735 JSON

CVE-2016-8735 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 90.3% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-06-02.

Description

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS90.34% — more likely to be exploited than 100% of all CVEs
On CISA KEVyes — remediate by 2023-06-02
Public exploitnone known
Published2017-04-06
Last modified2026-08-25

CISA KEV

NameApache Tomcat Remote Code Execution Vulnerability
Added2023-05-12
Due2023-06-02
Vendor / productApache / Tomcat
Ransomware usenone reported

Affected (19)

VendorProduct
apachetomcat
canonicalubuntu linux
debiandebian linux
netapp7-mode transition tool
netapponcommand insight
netapponcommand shift
netappsnap creator framework
oracleagile engineering data management
oracleagile product lifecycle management
oraclecommunications application session controller
oraclecommunications instant messaging server
oraclecommunications interactive session recorder
oraclehospitality guest access
oraclemicros relate crm software
oraclemicros retail xbri loss prevention
oraclemysql enterprise monitor
oracleretail convenience and fuel pos software
oracletransportation management
redhatjboss enterprise web server

References

→ the Explorer  ·  watch your stack  ·  NVD