9.8

CVE-2016-8735

Warnung
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version < 6.0.48
Apache ≫ Tomcat Version >= 7.0.0 < 7.0.73
Apache ≫ Tomcat Version >= 8.0 < 8.0.39
Apache ≫ Tomcat Version >= 8.5.0 < 8.5.7
Apache ≫ Tomcat Version 9.0.0 Update -
Apache ≫ Tomcat Version 9.0.0 Update milestone1
Apache ≫ Tomcat Version 9.0.0 Update milestone10
Apache ≫ Tomcat Version 9.0.0 Update milestone11
Apache ≫ Tomcat Version 9.0.0 Update milestone2
Apache ≫ Tomcat Version 9.0.0 Update milestone3
Apache ≫ Tomcat Version 9.0.0 Update milestone4
Apache ≫ Tomcat Version 9.0.0 Update milestone5
Apache ≫ Tomcat Version 9.0.0 Update milestone6
Apache ≫ Tomcat Version 9.0.0 Update milestone7
Apache ≫ Tomcat Version 9.0.0 Update milestone8
Apache ≫ Tomcat Version 9.0.0 Update milestone9
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Netapp ≫ Oncommand Insight Version -
Netapp ≫ Oncommand Shift Version -
Debian ≫ Debian Linux Version 8.0
Oracle ≫ Hospitality Guest Access Version 4.2.0
Oracle ≫ Hospitality Guest Access Version 4.2.1
Oracle ≫ Mysql Enterprise Monitor Version <= 3.2.8.2223
Oracle ≫ Mysql Enterprise Monitor Version >= 3.3.0 <= 3.3.4.3247
Oracle ≫ Mysql Enterprise Monitor Version >= 3.4.0 <= 3.4.2.4181
Oracle ≫ Transportation Management Version 6.3.0
Oracle ≫ Transportation Management Version 6.3.1
Oracle ≫ Transportation Management Version 6.3.2
Oracle ≫ Transportation Management Version 6.3.3
Oracle ≫ Transportation Management Version 6.3.4
Oracle ≫ Transportation Management Version 6.3.5
Oracle ≫ Transportation Management Version 6.3.6
Oracle ≫ Transportation Management Version 6.3.7

12.05.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Apache Tomcat Remote Code Execution Vulnerability

Schwachstelle

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 90.34% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
Patch
Third Party Advisory
http://tomcat.apache.org/security-6.html
Vendor Advisory
Release Notes
http://tomcat.apache.org/security-7.html
Vendor Advisory
Release Notes
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
Patch
Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
Patch
Third Party Advisory
http://tomcat.apache.org/security-8.html
Vendor Advisory
Release Notes
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
Patch
Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Patch
Third Party Advisory
http://tomcat.apache.org/security-9.html
Vendor Advisory
Release Notes
http://www.securitytracker.com/id/1037331
Third Party Advisory
Broken Link
VDB Entry
http://www.debian.org/security/2016/dsa-3738
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20180607-0001/
Third Party Advisory
https://usn.ubuntu.com/4557-1/
Third Party Advisory
http://seclists.org/oss-sec/2016/q4/502
Third Party Advisory
Mailing List
Mitigation
http://svn.apache.org/viewvc?view=revision&revision=1767644
Patch
Broken Link
http://svn.apache.org/viewvc?view=revision&revision=1767656
Patch
Broken Link
http://svn.apache.org/viewvc?view=revision&revision=1767676
Patch
Broken Link
http://svn.apache.org/viewvc?view=revision&revision=1767684
Patch
Broken Link
http://www.securityfocus.com/bid/94463
Third Party Advisory
Broken Link
VDB Entry
https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
http://rhn.redhat.com/errata/RHSA-2017-0457.html
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:0455
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:0456
Third Party Advisory
https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E
Patch
Mailing List
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-8735
US Government Resource