CVE-2016-8735
Apache Software Foundation Apache Tomcat
Published 6 Apr 2017 · updated 25 Aug 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 12 May 2023, with a remediation deadline of 2 Jun 2023 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
References
- rhn.redhat.com/errata/RHSA-2017-0457.html · Third Party Advisory
- seclists.org/oss-sec/2016/q4/502 · Mailing List, Mitigation, Third Party Advisory
- svn.apache.org/viewvc?view=revision&revision=1767644 · Broken Link, Patch
- svn.apache.org/viewvc?view=revision&revision=1767656 · Broken Link, Patch
- svn.apache.org/viewvc?view=revision&revision=1767676 · Broken Link, Patch
- svn.apache.org/viewvc?view=revision&revision=1767684 · Broken Link, Patch
- tomcat.apache.org/security-6.html · Release Notes, Vendor Advisory
- tomcat.apache.org/security-7.html · Release Notes, Vendor Advisory
- tomcat.apache.org/security-8.html · Release Notes, Vendor Advisory
- tomcat.apache.org/security-9.html · Release Notes, Vendor Advisory
- www.debian.org/security/2016/dsa-3738 · Mailing List, Third Party Advisory
- www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html · Patch, Third Party Advisory
- www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html · Patch, Third Party Advisory
- www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html · Patch, Third Party Advisory
- www.securityfocus.com/bid/94463 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id/1037331 · Broken Link, Third Party Advisory, VDB Entry
- access.redhat.com/errata/RHSA-2017:0455 · Third Party Advisory
- access.redhat.com/errata/RHSA-2017:0456 · Third Party Advisory
- lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E · Mailing List, Patch
- lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E · Mailing List, Patch
- lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E · Mailing List, Patch
- lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E · Mailing List, Patch
- lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E · Mailing List, Patch
- lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E · Mailing List, Patch
- lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E · Mailing List, Patch