Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
History
13 Mar 2025, 21:00
Type | Values Removed | Values Added |
---|---|---|
References | () http://svn.apache.org/viewvc?view=revision&revision=1767644 - Patch, Broken Link | |
References | () http://svn.apache.org/viewvc?view=revision&revision=1767656 - Patch, Broken Link | |
References | () http://svn.apache.org/viewvc?view=revision&revision=1767676 - Patch, Broken Link | |
References | () http://svn.apache.org/viewvc?view=revision&revision=1767684 - Patch, Broken Link |
Information
Published : 2017-04-06 21:59
Updated : 2025-04-20 01:37
NVD link : CVE-2016-8735
Mitre link : CVE-2016-8735
CVE.ORG link : CVE-2016-8735
JSON object : View
Products Affected
oracle
- retail_convenience_and_fuel_pos_software
- agile_engineering_data_management
- communications_interactive_session_recorder
- transportation_management
- hospitality_guest_access
- micros_retail_xbri_loss_prevention
- communications_application_session_controller
- micros_relate_crm_software
- agile_plm
- communications_instant_messaging_server
- mysql_enterprise_monitor
netapp
- oncommand_shift
- snap_creator_framework
- 7-mode_transition_tool
- oncommand_insight
canonical
- ubuntu_linux
debian
- debian_linux
redhat
- jboss_enterprise_web_server
apache
- tomcat
CWE