CVE-2016-8735 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 90.3% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2023-06-02.
Description
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 90.34% — more likely to be exploited than 100% of all CVEs |
| On CISA KEV | yes — remediate by 2023-06-02 |
| Public exploit | none known |
| Published | 2017-04-06 |
| Last modified | 2026-08-25 |
CISA KEV
| Name | Apache Tomcat Remote Code Execution Vulnerability |
|---|---|
| Added | 2023-05-12 |
| Due | 2023-06-02 |
| Vendor / product | Apache / Tomcat |
| Ransomware use | none reported |
Affected (19)
| Vendor | Product |
|---|---|
| apache | tomcat |
| canonical | ubuntu linux |
| debian | debian linux |
| netapp | 7-mode transition tool |
| netapp | oncommand insight |
| netapp | oncommand shift |
| netapp | snap creator framework |
| oracle | agile engineering data management |
| oracle | agile product lifecycle management |
| oracle | communications application session controller |
| oracle | communications instant messaging server |
| oracle | communications interactive session recorder |
| oracle | hospitality guest access |
| oracle | micros relate crm software |
| oracle | micros retail xbri loss prevention |
| oracle | mysql enterprise monitor |
| oracle | retail convenience and fuel pos software |
| oracle | transportation management |
| redhat | jboss enterprise web server |
References
- http://rhn.redhat.com/errata/RHSA-2017-0457.html
- http://seclists.org/oss-sec/2016/q4/502
- http://svn.apache.org/viewvc?view=revision&revision=1767644
- http://svn.apache.org/viewvc?view=revision&revision=1767656
- http://svn.apache.org/viewvc?view=revision&revision=1767676
- http://svn.apache.org/viewvc?view=revision&revision=1767684
- http://tomcat.apache.org/security-6.html
- http://tomcat.apache.org/security-7.html
- http://tomcat.apache.org/security-8.html
- http://tomcat.apache.org/security-9.html
- http://www.debian.org/security/2016/dsa-3738
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.securityfocus.com/bid/94463
- http://www.securitytracker.com/id/1037331
- https://access.redhat.com/errata/RHSA-2017:0455
- https://access.redhat.com/errata/RHSA-2017:0456
- https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E
→ the Explorer · watch your stack · NVD