CVE-2016-8735

Aliases:GHSA-cw54-59pw-4g8c
Advisory lineage Upstream: 0 Downstream: 15
Analyzed
Published: 06 Apr 2017, 21:00
Last modified:21 Oct 2025, 23:55

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
93.81% CRITICAL
94% probability -0.16%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Apr 2017, 21:00
Published
Vulnerability first disclosed
12 May 2023, 00:00
Added to CISA KEV
Apache Tomcat Remote Code Execution Vulnerability
02 Jun 2023, 00:00
CISA Remediation Due
Apply updates per vendor instructions.
21 Oct 2025, 23:55
Last Modified
Vulnerability information updated

Description

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v3.0CRITICALScore: 9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 93.81% Percentile: 100%

Affected Systems

  • apache software foundationapache tomcat

    < 6.0.48 | 7.x before 7.0.73 | 8.x before 8.0.39 | 8.5.x before 8.5.7 | 9.x before 9.0.0.M12

  • UnknownTomcat

    < 6.0.48 | ≥ 7.0.0, < 7.0.73 | ≥ 8.0, < 8.0.39 | ≥ 8.5.0, < 8.5.7 | 9.0.0 | 9.0.0:milestone1 | 9.0.0:milestone10 | 9.0.0:milestone11 | 9.0.0:milestone2 | 9.0.0:milestone3 | 9.0.0:milestone4 | 9.0.0:milestone5 | 9.0.0:milestone6 | 9.0.0:milestone7 | 9.0.0:milestone8 | 9.0.0:milestone9

  • canonicalubuntu_linux

    16.04

  • debiandebian_linux

    8.0

  • org.apache.tomcattomcat-catalina

    < 6.0.48 | ≥ 7.0.0, < 7.0.73 | ≥ 8.0.0, < 8.0.39 | ≥ 8.5.0, < 8.5.7 | ≥ 9.0.0.M1, < 9.0.0.M12

  • org.apache.tomcattomcat-catalina-jmx-remote

    < 6.0.48 | ≥ 7.0.0, < 7.0.73 | ≥ 8.0.0, < 8.0.39 | ≥ 8.5.0, < 8.5.7 | ≥ 9.0.0.M1, < 9.0.0.M12

  • netapp7-mode_transition_tool

    na

  • netapponcommand_insight

    na

  • netapponcommand_shift

    na

  • netappsnap_creator_framework

    na

  • oracleagile_engineering_data_management

    6.1.3 | 6.2.0 | 6.2.1.0

  • oracleagile_plm

    9.3.5 | 9.3.6

  • oraclecommunications_application_session_controller

    3.7.1 | 3.8.0

  • oraclecommunications_instant_messaging_server

    10.0.1

  • oraclecommunications_interactive_session_recorder

    6.0 | 6.1 | 6.2

  • oraclehospitality_guest_access

    4.2.0 | 4.2.1

  • oraclemicros_relate_crm_software

    10.8 | 11.4

  • oraclemicros_retail_xbri_loss_prevention

    10.0.1 | 10.5.0 | 10.6.0 | 10.7.7 | 10.8.0 | 10.8.1

  • oraclemysql_enterprise_monitor

    ≤ 3.2.8.2223 | ≥ 3.3.0, ≤ 3.3.4.3247 | ≥ 3.4.0, ≤ 3.4.2.4181

  • oracleretail_convenience_and_fuel_pos_software

    2.1.132

  • oracletransportation_management

    6.3.0 | 6.3.1 | 6.3.2 | 6.3.3 | 6.3.4 | 6.3.5 | 6.3.6 | 6.3.7

  • redhatjboss_enterprise_web_server

    3.0.0

References (62)