← Back

CVE-2016-8735

Published: Apr 6, 2017Modified: Apr 21, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

Affected (56)

Show all products
1 product
Tomcat
1 product
Ubuntu Linux
4 products
7 Mode Transition Tool
Oncommand Insight
Oncommand Shift
Snap Creator Framework
1 product
Debian Linux
1 product
Jboss Enterprise Web Server
11 products
Agile Engineering Data Management
Agile Plm
Hospitality Guest Access
Micros Relate Crm Software
Mysql Enterprise Monitor
Transportation Management
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Before 6.0.48
From 7.0.0 to 7.0.73
From 8.0 to 8.0.39
From 8.5.0 to 8.5.7
Version 9.0.0
Version 9.0.0 milestone10
Version 9.0.0 milestone11
Version 9.0.0 milestone1
Version 9.0.0 milestone2
Version 9.0.0 milestone3
Version 9.0.0 milestone4
Version 9.0.0 milestone5
Version 9.0.0 milestone6
Version 9.0.0 milestone7
Version 9.0.0 milestone8
Version 9.0.0 milestone9
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 16.04
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.0.0
Configuration F
33 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 6.1.3
Version 6.2.0
Version 6.2.1.0
Oracle
Version 9.3.5
Version 9.3.6
Oracle
Version 3.7.1
Version 3.8.0
Version 10.0.1
Oracle
Version 6.0
Version 6.1
Version 6.2
Oracle
Version 4.2.0
Version 4.2.1
Oracle
Version 10.8
Version 11.4
Oracle
Version 10.0.1
Version 10.5.0
Version 10.6.0
Version 10.7.7
Version 10.8.0
Version 10.8.1
Oracle
Up to 3.2.8.2223
From 3.3.0 to 3.3.4.3247
From 3.4.0 to 3.4.2.4181
Version 2.1.132
Oracle
Version 6.3.0
Version 6.3.1
Version 6.3.2
Version 6.3.3
Version 6.3.4
Version 6.3.5
Version 6.3.6
Version 6.3.7

References (73)

Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Mailing ListMitigationThird Party Advisory
Source: security@apache.org
Broken LinkPatch
Source: security@apache.org
Broken LinkPatch
Source: security@apache.org
Broken LinkPatch
Source: security@apache.org
Broken LinkPatch
Source: security@apache.org
Release NotesVendor Advisory
Source: security@apache.org
Release NotesVendor Advisory
Source: security@apache.org
Release NotesVendor Advisory
Source: security@apache.org
Release NotesVendor Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Broken LinkThird Party AdvisoryVDB Entry
Source: security@apache.org
Broken LinkThird Party AdvisoryVDB Entry
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.