9.8
CVE-2016-8735
- EPSS 90.34%
- Veröffentlicht 06.04.2017 21:59:00
- Zuletzt bearbeitet 25.08.2026 16:28:27
- Erkennungen
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Netapp ≫ 7-mode Transition Tool Version -
Netapp ≫ Oncommand Insight Version -
Netapp ≫ Oncommand Shift Version -
Netapp ≫ Snap Creator Framework Version -
Debian ≫ Debian Linux Version 8.0
Redhat ≫ Jboss Enterprise Web Server Version 3.0.0
Oracle ≫ Agile Engineering Data Management Version 6.1.3
Oracle ≫ Agile Engineering Data Management Version 6.2.0
Oracle ≫ Agile Engineering Data Management Version 6.2.1.0
Oracle ≫ Agile Product Lifecycle Management Version 9.3.5
Oracle ≫ Agile Product Lifecycle Management Version 9.3.6
Oracle ≫ Communications Application Session Controller Version 3.7.1
Oracle ≫ Communications Application Session Controller Version 3.8.0
Oracle ≫ Communications Instant Messaging Server Version 10.0.1
Oracle ≫ Communications Interactive Session Recorder Version 6.0
Oracle ≫ Communications Interactive Session Recorder Version 6.1
Oracle ≫ Communications Interactive Session Recorder Version 6.2
Oracle ≫ Hospitality Guest Access Version 4.2.0
Oracle ≫ Hospitality Guest Access Version 4.2.1
Oracle ≫ Micros Relate Crm Software Version 10.8
Oracle ≫ Micros Relate Crm Software Version 11.4
Oracle ≫ Micros Retail Xbri Loss Prevention Version 10.0.1
Oracle ≫ Micros Retail Xbri Loss Prevention Version 10.5.0
Oracle ≫ Micros Retail Xbri Loss Prevention Version 10.6.0
Oracle ≫ Micros Retail Xbri Loss Prevention Version 10.7.7
Oracle ≫ Micros Retail Xbri Loss Prevention Version 10.8.0
Oracle ≫ Micros Retail Xbri Loss Prevention Version 10.8.1
Oracle ≫ Mysql Enterprise Monitor Version <= 3.2.8.2223
Oracle ≫ Mysql Enterprise Monitor Version >= 3.3.0 <= 3.3.4.3247
Oracle ≫ Mysql Enterprise Monitor Version >= 3.4.0 <= 3.4.2.4181
Oracle ≫ Retail Convenience And Fuel Pos Software Version 2.1.132
Oracle ≫ Transportation Management Version 6.3.0
Oracle ≫ Transportation Management Version 6.3.1
Oracle ≫ Transportation Management Version 6.3.2
Oracle ≫ Transportation Management Version 6.3.3
Oracle ≫ Transportation Management Version 6.3.4
Oracle ≫ Transportation Management Version 6.3.5
Oracle ≫ Transportation Management Version 6.3.6
Oracle ≫ Transportation Management Version 6.3.7
12.05.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog
Apache Tomcat Remote Code Execution Vulnerability
SchwachstelleApache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 90.34% | 0.998 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
| CISA-ADP | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://tomcat.apache.org/security-6.html
http://tomcat.apache.org/security-7.html
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://tomcat.apache.org/security-8.html
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
http://tomcat.apache.org/security-9.html
http://www.securitytracker.com/id/1037331
http://www.debian.org/security/2016/dsa-3738
https://security.netapp.com/advisory/ntap-20180607-0001/
https://usn.ubuntu.com/4557-1/
http://seclists.org/oss-sec/2016/q4/502
http://svn.apache.org/viewvc?view=revision&revision=1767644
http://svn.apache.org/viewvc?view=revision&revision=1767656
http://svn.apache.org/viewvc?view=revision&revision=1767676
http://svn.apache.org/viewvc?view=revision&revision=1767684
http://www.securityfocus.com/bid/94463
https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E
http://rhn.redhat.com/errata/RHSA-2017-0457.html
https://access.redhat.com/errata/RHSA-2017:0455
https://access.redhat.com/errata/RHSA-2017:0456
https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-8735