CVE-2016-8735

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
apacheCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
apachetomcat
𝑥
< 6.0.48
apachetomcat
7.0.0 ≤
𝑥
< 7.0.73
apachetomcat
8.0 ≤
𝑥
< 8.0.39
apachetomcat
8.5.0 ≤
𝑥
< 8.5.7
apachetomcat
9.0.0
apachetomcat
9.0.0:milestone1
apachetomcat
9.0.0:milestone10
apachetomcat
9.0.0:milestone11
apachetomcat
9.0.0:milestone2
apachetomcat
9.0.0:milestone3
apachetomcat
9.0.0:milestone4
apachetomcat
9.0.0:milestone5
apachetomcat
9.0.0:milestone6
apachetomcat
9.0.0:milestone7
apachetomcat
9.0.0:milestone8
apachetomcat
9.0.0:milestone9
canonicalubuntu_linux
16.04
netapp7-mode_transition_tool
-
netapponcommand_insight
-
netapponcommand_shift
-
netappsnap_creator_framework
-
debiandebian_linux
8.0
redhatjboss_enterprise_web_server
3.0.0
oracleagile_engineering_data_management
6.1.3
oracleagile_engineering_data_management
6.2.0
oracleagile_engineering_data_management
6.2.1.0
oracleagile_plm
9.3.5
oracleagile_plm
9.3.6
oraclecommunications_application_session_controller
3.7.1
oraclecommunications_application_session_controller
3.8.0
oraclecommunications_instant_messaging_server
10.0.1
oraclecommunications_interactive_session_recorder
6.0
oraclecommunications_interactive_session_recorder
6.1
oraclecommunications_interactive_session_recorder
6.2
oraclehospitality_guest_access
4.2.0
oraclehospitality_guest_access
4.2.1
oraclemicros_relate_crm_software
10.8
oraclemicros_relate_crm_software
11.4
oraclemicros_retail_xbri_loss_prevention
10.0.1
oraclemicros_retail_xbri_loss_prevention
10.5.0
oraclemicros_retail_xbri_loss_prevention
10.6.0
oraclemicros_retail_xbri_loss_prevention
10.7.7
oraclemicros_retail_xbri_loss_prevention
10.8.0
oraclemicros_retail_xbri_loss_prevention
10.8.1
oraclemysql_enterprise_monitor
𝑥
≤ 3.2.8.2223
oraclemysql_enterprise_monitor
3.3.0 ≤
𝑥
≤ 3.3.4.3247
oraclemysql_enterprise_monitor
3.4.0 ≤
𝑥
≤ 3.4.2.4181
oracleretail_convenience_and_fuel_pos_software
2.1.132
oracletransportation_management
6.3.0
oracletransportation_management
6.3.1
oracletransportation_management
6.3.2
oracletransportation_management
6.3.3
oracletransportation_management
6.3.4
oracletransportation_management
6.3.5
oracletransportation_management
6.3.6
oracletransportation_management
6.3.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tomcat9
bullseye (security)
9.0.43-2~deb11u10
fixed
bullseye
9.0.43-2~deb11u10
fixed
bookworm
9.0.70-2
fixed
sid
9.0.95-1
fixed
trixie
9.0.95-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tomcat6
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
impish
dne
hirsute
dne
groovy
dne
focal
dne
eoan
dne
disco
dne
cosmic
dne
bionic
dne
artful
dne
zesty
dne
yakkety
dne
xenial
Fixed 6.0.45+dfsg-1ubuntu0.1
released
trusty
needed
precise
Fixed 6.0.35-1ubuntu3.9
released
tomcat7
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
impish
dne
hirsute
dne
groovy
dne
focal
dne
eoan
dne
disco
dne
cosmic
not-affected
bionic
not-affected
artful
not-affected
zesty
not-affected
yakkety
ignored
xenial
Fixed 7.0.68-1ubuntu0.3
released
trusty
Fixed 7.0.52-1ubuntu0.8
released
precise
ignored
tomcat8
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
impish
dne
hirsute
dne
groovy
dne
focal
dne
eoan
dne
disco
dne
cosmic
Fixed 8.0.38-2ubuntu1
released
bionic
Fixed 8.0.38-2ubuntu1
released
artful
Fixed 8.0.38-2ubuntu1
released
zesty
Fixed 8.0.38-2ubuntu1
released
yakkety
Fixed 8.0.37-1ubuntu0.1
released
xenial
Fixed 8.0.32-1ubuntu1.3
released
trusty
dne
precise
dne
References