Security
Loading…

CVE-2016-8735

CRITICALCVSS 9.8Known Exploited
Description

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.

Timeline
Published:April 6th, 2017 9:59 PM
Last modified:August 25th, 2026 4:28 PM
Added to KEV:May 12th, 2023
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2: 7.5

Affected Software
From NVD CPE configuration data

Vendors

apachecanonicalnetappdebianredhatoracle

Products

tomcatubuntu_linux7-mode_transition_tooloncommand_insightoncommand_shiftsnap_creator_frameworkdebian_linuxjboss_enterprise_web_serveragile_engineering_data_managementagile_product_lifecycle_managementcommunications_application_session_controllercommunications_instant_messaging_servercommunications_interactive_session_recorderhospitality_guest_accessmicros_relate_crm_softwaremicros_retail_xbri_loss_preventionmysql_enterprise_monitorretail_convenience_and_fuel_pos_softwaretransportation_management
References & Reports
Advisories, patches, and third-party reports

Source: NIST NVD · Data may lag official sources by up to one minute