← All CVEs

CVE-2016-8735

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2023-05-12Remediation due 2023-06-02

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

9.8
CVSS
90.3%
EPSS (exploit prob.)
100th
EPSS percentile
2017-04-06
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
apachetomcat< 6.0.48
apachetomcat>= 7.0.0, < 7.0.73
apachetomcat>= 8.0, < 8.0.39
apachetomcat>= 8.5.0, < 8.5.7
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
canonicalubuntu_linux16.04
netapp7-mode_transition_toolall versions
netapponcommand_insightall versions
netapponcommand_shiftall versions
netappsnap_creator_frameworkall versions
debiandebian_linux8.0
redhatjboss_enterprise_web_server3.0.0
oracleagile_engineering_data_management6.1.3
oracleagile_engineering_data_management6.2.0
oracleagile_engineering_data_management6.2.1.0
oracleagile_product_lifecycle_management9.3.5
oracleagile_product_lifecycle_management9.3.6
oraclecommunications_application_session_controller3.7.1
oraclecommunications_application_session_controller3.8.0
oraclecommunications_instant_messaging_server10.0.1
oraclecommunications_interactive_session_recorder6.0
oraclecommunications_interactive_session_recorder6.1
oraclecommunications_interactive_session_recorder6.2
oraclehospitality_guest_access4.2.0
oraclehospitality_guest_access4.2.1
oraclemicros_relate_crm_software10.8
oraclemicros_relate_crm_software11.4
oraclemicros_retail_xbri_loss_prevention10.0.1
oraclemicros_retail_xbri_loss_prevention10.5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-8735