cbcvebase.
CVE-2016-8735
published 2017-04-06

CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if…

PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-06-02
Exploited in the wild
EPSS
90.34%
99.8th percentile
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
apachetomcat< 6.0.486.0.48
apachetomcat
apachetomcat
apachetomcat>= 7.0.0 < 7.0.737.0.73
apachetomcat>= 8.0 < 8.0.398.0.39
apachetomcat>= 8.5.0 < 8.5.78.5.7
canonicalubuntu_linux
debiandebian_linux
debiantomcat9
oracleagile_engineering_data_management
oracleagile_engineering_data_management
oracleagile_engineering_data_management
oracleagile_plm
oracleagile_plm
oraclecommunications_application_session_controller
oraclecommunications_application_session_controller
oraclecommunications_instant_messaging_server
oraclecommunications_interactive_session_recorder
oraclecommunications_interactive_session_recorder
oraclecommunications_interactive_session_recorder
oraclehospitality_guest_access
oraclehospitality_guest_access
oraclemicros_relate_crm_software
oraclemicros_relate_crm_software
oraclemicros_retail_xbri_loss_prevention

Detection & IOCsextracted from sources · hover to see the quote

otherUnicastRef2
bytes
4a524d4900024b
bytes
000c31302e36352e3135372e313000000000
bytes
50aced00057722000000000000000000000000000000000000000000000000000244154dc9d4e63bdf7400066a6d78726d69
bytes
50aced000577220000000000000002000000000000000000000000000000000001f6b6898d8bf28643757200185b4c6a6176612e726d692e7365727665722e4f626a49443b871300b8d02c647e02000070787000000001737200156a6176612e726d692e7365727665722e4f626a4944a75efa128ddce55c0200024a00066f626a4e756d4c000573706163657400154c6a6176612f726d692f7365727665722f5549443b7078702d4f7f1ffa7877b4737200136a6176612e726d692e7365727665722e5549440f12700dbf364f12020003530005636f756e744a000474696d65490006756e69717565707870800100000192f5ff701a9cb3f67477088000000000000000737200126a6176612e726d692e6467632e4c65617365b0b5e2660c4adc340200024a000576616c75654c0004766d69647400134c6a6176612f726d692f6467632f564d49443b70787000000000000927c0737200116a6176612e726d692e6467632e564d4944f8865bafa4a56db60200025b0004616464727400025b424c000375696471007e0003707870757200025b42acf317f8060854e002000070787000000008f1c6fcc113e4dd097371007e0005800100000192f6835b0fb632f8a1
bytes
43726564656e7469616c732073686f756c6420626520537472696e675b5d20696e7374656164206f66206a6176612e7574696c2e486173684d61707572
  • Exploit initiates a two-stage TCP connection: first to the RMI registry port, then to a dynamically resolved rmiServerPort extracted from the 'UnicastRef2' marker in the registry response.
  • Exploit delivers a Java serialized URLDNS gadget payload (magic bytes 'aced0005') over the RMI server port to trigger unsafe deserialization; a successful hit causes an outbound DNS callback to an OAST/interactsh URL.
  • Positive exploitation is confirmed by two conditions: (1) the response contains the hex-encoded string 'Credentials should be String[] instead of java.util.HashMapur', and (2) an interactsh DNS callback is received.
  • Shodan query 'product:"tomcat"' can be used to identify exposed Apache Tomcat instances for attack surface enumeration.
  • The vulnerability is only exploitable when JmxRemoteLifecycleListener is configured and JMX ports are network-reachable; monitor for unexpected inbound TCP connections to RMI/JMX ports.
  • ·The vulnerability only affects deployments where JmxRemoteLifecycleListener is explicitly configured; default Tomcat installations without this listener are not vulnerable.
  • ·JMXRemoteLifecycleListener is only included in EWS 2.x and JWS 3.x source distributions; binary distributions may not be affected.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_apache9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
vendor_ubuntu5.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.