cbcvebase.
CVE-2016-8735
published 2017-04-06

CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-06-02
Exploited in the wild
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
apachetomcat< 6.0.486.0.48
apachetomcat
apachetomcat
apachetomcat>= 7.0.0 < 7.0.737.0.73
apachetomcat>= 8.0 < 8.0.398.0.39
apachetomcat>= 8.5.0 < 8.5.78.5.7
canonicalubuntu_linux
debiandebian_linux
debiantomcat9
oracleagile_engineering_data_management
oracleagile_engineering_data_management
oracleagile_engineering_data_management
oracleagile_plm
oracleagile_plm
oraclecommunications_application_session_controller
oraclecommunications_application_session_controller
oraclecommunications_instant_messaging_server
oraclecommunications_interactive_session_recorder
oraclecommunications_interactive_session_recorder
oraclecommunications_interactive_session_recorder
oraclehospitality_guest_access
oraclehospitality_guest_access
oraclemicros_relate_crm_software
oraclemicros_relate_crm_software
oraclemicros_retail_xbri_loss_prevention

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa9.8CRITICAL
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL