CVE-2016-8735
Apache Tomcat Remote Code Execution Vulnerability
CVSS
9.8
Crítico
EPSS
90.3%
p100
KEV
SÍ
12 may 2023
Exploit Today
80
0-100
Publicado: 6 abr 2017 · Última mod.: 25 ago 2026
Producto
Apache / Tomcat
Vulnerabilidad
Apache Tomcat Remote Code Execution Vulnerability
Añadido a KEV
12 may 2023
Remediar antes de
2 jun 2023
Uso conocido en ransomware
No
Descripción resumida
Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.
Acción requerida
Apply updates per vendor instructions.
Notas
https://tomcat.apache.org/security-9.html; https://nvd.nist.gov/vuln/detail/CVE-2016-8735
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
- rhn.redhat.comhttp://rhn.redhat.com/errata/RHSA-2017-0457.html
- seclists.orghttp://seclists.org/oss-sec/2016/q4/502
- svn.apache.orghttp://svn.apache.org/viewvc?view=revision&revision=1767644
- svn.apache.orghttp://svn.apache.org/viewvc?view=revision&revision=1767656
- svn.apache.orghttp://svn.apache.org/viewvc?view=revision&revision=1767676
- svn.apache.orghttp://svn.apache.org/viewvc?view=revision&revision=1767684
- tomcat.apache.orghttp://tomcat.apache.org/security-6.html
- tomcat.apache.orghttp://tomcat.apache.org/security-7.html
- tomcat.apache.orghttp://tomcat.apache.org/security-8.html
- tomcat.apache.orghttp://tomcat.apache.org/security-9.html
- www.debian.orghttp://www.debian.org/security/2016/dsa-3738
- www.oracle.comhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- www.oracle.comhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- www.oracle.comhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- www.securityfocus.comhttp://www.securityfocus.com/bid/94463
- www.securitytracker.comhttp://www.securitytracker.com/id/1037331
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2017:0455
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2017:0456
- lists.apache.orghttps://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
- lists.apache.orghttps://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E