CVE-2016-8735
06.04.2017, 21:59
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | tomcat | 𝑥 < 6.0.48 |
| apache | tomcat | 7.0.0 ≤ 𝑥 < 7.0.73 |
| apache | tomcat | 8.0 ≤ 𝑥 < 8.0.39 |
| apache | tomcat | 8.5.0 ≤ 𝑥 < 8.5.7 |
| apache | tomcat | 9.0.0 |
| apache | tomcat | 9.0.0:milestone1 |
| apache | tomcat | 9.0.0:milestone10 |
| apache | tomcat | 9.0.0:milestone11 |
| apache | tomcat | 9.0.0:milestone2 |
| apache | tomcat | 9.0.0:milestone3 |
| apache | tomcat | 9.0.0:milestone4 |
| apache | tomcat | 9.0.0:milestone5 |
| apache | tomcat | 9.0.0:milestone6 |
| apache | tomcat | 9.0.0:milestone7 |
| apache | tomcat | 9.0.0:milestone8 |
| apache | tomcat | 9.0.0:milestone9 |
| canonical | ubuntu_linux | 16.04 |
| netapp | 7-mode_transition_tool | - |
| netapp | oncommand_insight | - |
| netapp | oncommand_shift | - |
| netapp | snap_creator_framework | - |
| debian | debian_linux | 8.0 |
| redhat | jboss_enterprise_web_server | 3.0.0 |
| oracle | agile_engineering_data_management | 6.1.3 |
| oracle | agile_engineering_data_management | 6.2.0 |
| oracle | agile_engineering_data_management | 6.2.1.0 |
| oracle | agile_plm | 9.3.5 |
| oracle | agile_plm | 9.3.6 |
| oracle | communications_application_session_controller | 3.7.1 |
| oracle | communications_application_session_controller | 3.8.0 |
| oracle | communications_instant_messaging_server | 10.0.1 |
| oracle | communications_interactive_session_recorder | 6.0 |
| oracle | communications_interactive_session_recorder | 6.1 |
| oracle | communications_interactive_session_recorder | 6.2 |
| oracle | hospitality_guest_access | 4.2.0 |
| oracle | hospitality_guest_access | 4.2.1 |
| oracle | micros_relate_crm_software | 10.8 |
| oracle | micros_relate_crm_software | 11.4 |
| oracle | micros_retail_xbri_loss_prevention | 10.0.1 |
| oracle | micros_retail_xbri_loss_prevention | 10.5.0 |
| oracle | micros_retail_xbri_loss_prevention | 10.6.0 |
| oracle | micros_retail_xbri_loss_prevention | 10.7.7 |
| oracle | micros_retail_xbri_loss_prevention | 10.8.0 |
| oracle | micros_retail_xbri_loss_prevention | 10.8.1 |
| oracle | mysql_enterprise_monitor | 𝑥 ≤ 3.2.8.2223 |
| oracle | mysql_enterprise_monitor | 3.3.0 ≤ 𝑥 ≤ 3.3.4.3247 |
| oracle | mysql_enterprise_monitor | 3.4.0 ≤ 𝑥 ≤ 3.4.2.4181 |
| oracle | retail_convenience_and_fuel_pos_software | 2.1.132 |
| oracle | transportation_management | 6.3.0 |
| oracle | transportation_management | 6.3.1 |
| oracle | transportation_management | 6.3.2 |
| oracle | transportation_management | 6.3.3 |
| oracle | transportation_management | 6.3.4 |
| oracle | transportation_management | 6.3.5 |
| oracle | transportation_management | 6.3.6 |
| oracle | transportation_management | 6.3.7 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| tomcat6 |
| ||||||||||||||||||||||||||||||||||||||
| tomcat7 |
| ||||||||||||||||||||||||||||||||||||||
| tomcat8 |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| tomcat |
| ||||||||||||||||
| tomcat-admin-webapps |
| ||||||||||||||||
| tomcat-docs-webapp |
| ||||||||||||||||
| tomcat-el-2_2-api |
| ||||||||||||||||
| tomcat-el-3_0-api |
| ||||||||||||||||
| tomcat-javadoc |
| ||||||||||||||||
| tomcat-jsp-2_2-api |
| ||||||||||||||||
| tomcat-jsp-2_3-api |
| ||||||||||||||||
| tomcat-lib |
| ||||||||||||||||
| tomcat-servlet-3_0-api |
| ||||||||||||||||
| tomcat-servlet-3_1-api |
| ||||||||||||||||
| tomcat-servlet-4_0-api |
| ||||||||||||||||
| tomcat-webapps |
|
References