CVE-2016-8735
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2023-05-12Remediation due 2023-06-02
A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
9.8
CVSS
90.3%
EPSS (exploit prob.)
100th
EPSS percentile
2017-04-06
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | tomcat | < 6.0.48 |
| apache | tomcat | >= 7.0.0, < 7.0.73 |
| apache | tomcat | >= 8.0, < 8.0.39 |
| apache | tomcat | >= 8.5.0, < 8.5.7 |
| apache | tomcat | 9.0.0 |
| apache | tomcat | 9.0.0 |
| apache | tomcat | 9.0.0 |
| apache | tomcat | 9.0.0 |
| apache | tomcat | 9.0.0 |
| apache | tomcat | 9.0.0 |
| apache | tomcat | 9.0.0 |
| apache | tomcat | 9.0.0 |
| apache | tomcat | 9.0.0 |
| apache | tomcat | 9.0.0 |
| apache | tomcat | 9.0.0 |
| apache | tomcat | 9.0.0 |
| canonical | ubuntu_linux | 16.04 |
| netapp | 7-mode_transition_tool | all versions |
| netapp | oncommand_insight | all versions |
| netapp | oncommand_shift | all versions |
| netapp | snap_creator_framework | all versions |
| debian | debian_linux | 8.0 |
| redhat | jboss_enterprise_web_server | 3.0.0 |
| oracle | agile_engineering_data_management | 6.1.3 |
| oracle | agile_engineering_data_management | 6.2.0 |
| oracle | agile_engineering_data_management | 6.2.1.0 |
| oracle | agile_product_lifecycle_management | 9.3.5 |
| oracle | agile_product_lifecycle_management | 9.3.6 |
| oracle | communications_application_session_controller | 3.7.1 |
| oracle | communications_application_session_controller | 3.8.0 |
| oracle | communications_instant_messaging_server | 10.0.1 |
| oracle | communications_interactive_session_recorder | 6.0 |
| oracle | communications_interactive_session_recorder | 6.1 |
| oracle | communications_interactive_session_recorder | 6.2 |
| oracle | hospitality_guest_access | 4.2.0 |
| oracle | hospitality_guest_access | 4.2.1 |
| oracle | micros_relate_crm_software | 10.8 |
| oracle | micros_relate_crm_software | 11.4 |
| oracle | micros_retail_xbri_loss_prevention | 10.0.1 |
| oracle | micros_retail_xbri_loss_prevention | 10.5.0 |
Check a specific version with /api/v1/cve/match.
References
- http://rhn.redhat.com/errata/RHSA-2017-0457.html
- http://seclists.org/oss-sec/2016/q4/502
- http://svn.apache.org/viewvc?view=revision&revision=1767644
- http://svn.apache.org/viewvc?view=revision&revision=1767656
- http://svn.apache.org/viewvc?view=revision&revision=1767676
- http://svn.apache.org/viewvc?view=revision&revision=1767684
- http://tomcat.apache.org/security-6.html
- http://tomcat.apache.org/security-7.html
- http://tomcat.apache.org/security-8.html
- http://tomcat.apache.org/security-9.html
- http://www.debian.org/security/2016/dsa-3738
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.securityfocus.com/bid/94463
- http://www.securitytracker.com/id/1037331
- https://access.redhat.com/errata/RHSA-2017:0455
- https://access.redhat.com/errata/RHSA-2017:0456
- https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-8735