CRITICAL · 9.8

CVE-2016-8735

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an atta...

Vulnerability Description

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ApacheTomcat< 6.0.48
CanonicalUbuntu Linux16.04
Netapp7-Mode Transition Tool-
NetappOncommand Insight-
NetappOncommand Shift-
NetappSnap Creator Framework-
DebianDebian Linux8.0
RedhatJboss Enterprise Web Server3.0.0
OracleAgile Engineering Data Management6.1.3
OracleAgile Plm9.3.5
OracleCommunications Application Session Controller3.7.1
OracleCommunications Instant Messaging Server10.0.1
OracleCommunications Interactive Session Recorder6.0
OracleHospitality Guest Access4.2.0
OracleMicros Relate Crm Software10.8
OracleMicros Retail Xbri Loss Prevention10.0.1
OracleMysql Enterprise Monitor<= 3.2.8.2223
OracleRetail Convenience And Fuel Pos Software2.1.132
OracleTransportation Management6.3.0

References

FAQ

What is CVE-2016-8735?

CVE-2016-8735 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an atta...

How severe is CVE-2016-8735?

CVE-2016-8735 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2016-8735?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat, Canonical Ubuntu Linux, Netapp 7-Mode Transition Tool, Netapp Oncommand Insight, Netapp Oncommand Shift.