CVE-2016-8735
CRITICALCVSS 9.8Known ExploitedCISA Known Exploited Vulnerability
https://tomcat.apache.org/security-9.html; https://nvd.nist.gov/vuln/detail/CVE-2016-8735
Remediation deadline: June 2, 2023
Description
Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.
Timeline
Published:April 6th, 2017 9:59 PM
Last modified:August 25th, 2026 4:28 PM
Added to KEV:May 12th, 2023
CVSS Scoring
CVSS v3: 9.8 (CRITICAL)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2: 7.5
Affected Software
From NVD CPE configuration data
Vendors
apachecanonicalnetappdebianredhatoracle
Products
tomcatubuntu_linux7-mode_transition_tooloncommand_insightoncommand_shiftsnap_creator_frameworkdebian_linuxjboss_enterprise_web_serveragile_engineering_data_managementagile_product_lifecycle_managementcommunications_application_session_controllercommunications_instant_messaging_servercommunications_interactive_session_recorderhospitality_guest_accessmicros_relate_crm_softwaremicros_retail_xbri_loss_preventionmysql_enterprise_monitorretail_convenience_and_fuel_pos_softwaretransportation_management
References & Reports
Advisories, patches, and third-party reports
- http://rhn.redhat.com/errata/RHSA-2017-0457.htmlThird Party Advisory
- http://seclists.org/oss-sec/2016/q4/502Mailing List
- http://svn.apache.org/viewvc?view=revision&revision=1767644Broken Link
- http://svn.apache.org/viewvc?view=revision&revision=1767656Broken Link
- http://svn.apache.org/viewvc?view=revision&revision=1767676Broken Link
- http://svn.apache.org/viewvc?view=revision&revision=1767684Broken Link
- http://tomcat.apache.org/security-6.htmlRelease Notes
- http://tomcat.apache.org/security-7.htmlRelease Notes
- http://tomcat.apache.org/security-8.htmlRelease Notes
- http://tomcat.apache.org/security-9.htmlRelease Notes
- http://www.debian.org/security/2016/dsa-3738Mailing List
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlPatch
- http://www.securityfocus.com/bid/94463Broken Link
- http://www.securitytracker.com/id/1037331Broken Link
- https://access.redhat.com/errata/RHSA-2017:0455Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0456Third Party Advisory
- https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3EMailing List
- https://security.netapp.com/advisory/ntap-20180607-0001/Third Party Advisory
- https://usn.ubuntu.com/4557-1/Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlPatch
- http://rhn.redhat.com/errata/RHSA-2017-0457.htmlThird Party Advisory
- http://seclists.org/oss-sec/2016/q4/502Mailing List
- http://svn.apache.org/viewvc?view=revision&revision=1767644Broken Link
- http://svn.apache.org/viewvc?view=revision&revision=1767656Broken Link
- http://svn.apache.org/viewvc?view=revision&revision=1767676Broken Link
- http://svn.apache.org/viewvc?view=revision&revision=1767684Broken Link
- http://tomcat.apache.org/security-6.htmlRelease Notes
- http://tomcat.apache.org/security-7.htmlRelease Notes
- http://tomcat.apache.org/security-8.htmlRelease Notes
- http://tomcat.apache.org/security-9.htmlRelease Notes
- http://www.debian.org/security/2016/dsa-3738Mailing List
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlPatch
- http://www.securityfocus.com/bid/94463Broken Link
- http://www.securitytracker.com/id/1037331Broken Link
- https://access.redhat.com/errata/RHSA-2017:0455Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0456Third Party Advisory
- https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3EMailing List
- https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3EMailing List
- https://security.netapp.com/advisory/ntap-20180607-0001/Third Party Advisory
- https://usn.ubuntu.com/4557-1/Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlPatch
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-8735US Government Resource
Source: NIST NVD · Data may lag official sources by up to one minute