CyberSec.Space Logo
Back to CVE Browser

CVE-2016-8735

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score43.3920%
EPSS Percentile96.52th
PublishedApr 6, 2017
Last ModifiedApr 21, 2026

Vulnerability Description

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

Affected Platforms (CPE)

πŸ“¦
Apache

Tomcat

< 6.0.48
πŸ“¦
Apache

Tomcat

>= 7.0.0 and < 7.0.73
πŸ“¦
Apache

Tomcat

>= 8.0 and < 8.0.39
πŸ“¦
Apache

Tomcat

>= 8.5.0 and < 8.5.7
πŸ“¦
Apache

Tomcat

= 9.0.0
πŸ“¦
Apache

Tomcat

= 9.0.0
πŸ“¦
Apache

Tomcat

= 9.0.0
πŸ“¦
Apache

Tomcat

= 9.0.0
πŸ“¦
Apache

Tomcat

= 9.0.0
πŸ“¦
Apache

Tomcat

= 9.0.0
πŸ“¦
Apache

Tomcat

= 9.0.0
πŸ“¦
Apache

Tomcat

= 9.0.0
πŸ“¦
Apache

Tomcat

= 9.0.0
πŸ“¦
Apache

Tomcat

= 9.0.0
πŸ“¦
Apache

Tomcat

= 9.0.0
πŸ“¦
Apache

Tomcat

= 9.0.0
πŸ’»
Canonical

Ubuntu Linux

= 16.04
πŸ“¦
Netapp

7 Mode Transition Tool

All versions
πŸ“¦
Netapp

Oncommand Insight

All versions
πŸ“¦
Netapp

Oncommand Shift

All versions
πŸ“¦
Netapp

Snap Creator Framework

All versions
πŸ’»
Debian

Debian Linux

= 8.0
πŸ“¦
Redhat

Jboss Enterprise Web Server

= 3.0.0
πŸ“¦
Oracle

Agile Engineering Data Management

= 6.1.3
πŸ“¦
Oracle

Agile Engineering Data Management

= 6.2.0
πŸ“¦
Oracle

Agile Engineering Data Management

= 6.2.1.0
πŸ“¦
Oracle

Agile Plm

= 9.3.5
πŸ“¦
Oracle

Agile Plm

= 9.3.6
πŸ“¦
Oracle

Communications Application Session Controller

= 3.7.1
πŸ“¦
Oracle

Communications Application Session Controller

= 3.8.0
πŸ“¦
Oracle

Communications Instant Messaging Server

= 10.0.1
πŸ“¦
Oracle

Communications Interactive Session Recorder

= 6.0
πŸ“¦
Oracle

Communications Interactive Session Recorder

= 6.1
πŸ“¦
Oracle

Communications Interactive Session Recorder

= 6.2
πŸ“¦
Oracle

Hospitality Guest Access

= 4.2.0
πŸ“¦
Oracle

Hospitality Guest Access

= 4.2.1
πŸ“¦
Oracle

Micros Relate Crm Software

= 10.8
πŸ“¦
Oracle

Micros Relate Crm Software

= 11.4
πŸ“¦
Oracle

Micros Retail Xbri Loss Prevention

= 10.0.1
πŸ“¦
Oracle

Micros Retail Xbri Loss Prevention

= 10.5.0
πŸ“¦
Oracle

Micros Retail Xbri Loss Prevention

= 10.6.0
πŸ“¦
Oracle

Micros Retail Xbri Loss Prevention

= 10.7.7
πŸ“¦
Oracle

Micros Retail Xbri Loss Prevention

= 10.8.0
πŸ“¦
Oracle

Micros Retail Xbri Loss Prevention

= 10.8.1
πŸ“¦
Oracle

Mysql Enterprise Monitor

<= 3.2.8.2223
πŸ“¦
Oracle

Mysql Enterprise Monitor

>= 3.3.0 and <= 3.3.4.3247
πŸ“¦
Oracle

Mysql Enterprise Monitor

>= 3.4.0 and <= 3.4.2.4181
πŸ“¦
Oracle

Retail Convenience And Fuel Pos Software

= 2.1.132
πŸ“¦
Oracle

Transportation Management

= 6.3.0
πŸ“¦
Oracle

Transportation Management

= 6.3.1
πŸ“¦
Oracle

Transportation Management

= 6.3.2
πŸ“¦
Oracle

Transportation Management

= 6.3.3
πŸ“¦
Oracle

Transportation Management

= 6.3.4
πŸ“¦
Oracle

Transportation Management

= 6.3.5
πŸ“¦
Oracle

Transportation Management

= 6.3.6
πŸ“¦
Oracle

Transportation Management

= 6.3.7

References & Advisories

Related Vulnerabilities