// For flags

CVE-2016-8735

Apache Tomcat Remote Code Execution Vulnerability

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

Yes
*KEV

Decision

-
*SSVC
Descriptions

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

La ejecución remota de código es posible con Apache Tomcat en versiones anteriores a 6.0.48, 7.x en versiones anteriores a 7.0.73, 8.x en versiones anteriores a 8.0.39, 8.5.x en versiones anteriores a 8.5.7 y 9.x en versiones anteriores a 9.0.0.M12 si JmxRemoteLifecycleListener es utilizado y un atacante puede llegar a los puertos JMX. El problema existe porque este oyente no se actualizó por coherencia con el parche de Oracle CVE-2016-3427 que afectó a los tipos de credenciales.

The JmxRemoteLifecycleListener was not updated to take account of Oracle's fix for CVE-2016-3427. JMXRemoteLifecycleListener is only included in EWS 2.x and JWS 3.x source distributions. If you deploy a Tomcat instance built from source, using the EWS 2.x, or JWS 3.x distributions, an attacker could use this flaw to launch a remote code execution attack on your deployed instance.

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-10-18 CVE Reserved
  • 2016-12-18 CVE Published
  • 2023-05-12 Exploited in Wild
  • 2023-06-02 KEV Due Date
  • 2024-06-28 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- First Exploit
CWE
  • CWE-502: Deserialization of Untrusted Data
CAPEC
References (38)
URL Date SRC
URL Date SRC
http://svn.apache.org/viewvc?view=revision&revision=1767644 2024-06-27
http://svn.apache.org/viewvc?view=revision&revision=1767656 2024-06-27
http://svn.apache.org/viewvc?view=revision&revision=1767676 2024-06-27
http://svn.apache.org/viewvc?view=revision&revision=1767684 2024-06-27
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html 2024-06-27
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html 2024-06-27
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html 2024-06-27
https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E 2024-06-27
https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E 2024-06-27
https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E 2024-06-27
https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E 2024-06-27
https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E 2024-06-27
https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E 2024-06-27
https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E 2024-06-27
https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E 2024-06-27
https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E 2024-06-27
https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E 2024-06-27
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E 2024-06-27
https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E 2024-06-27
https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E 2024-06-27
https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E 2024-06-27
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html 2024-06-27
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html 2024-06-27
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
< 6.0.48
Search vendor "Apache" for product "Tomcat" and version " < 6.0.48"
-
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
>= 7.0.0 < 7.0.73
Search vendor "Apache" for product "Tomcat" and version " >= 7.0.0 < 7.0.73"
-
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
>= 8.0 < 8.0.39
Search vendor "Apache" for product "Tomcat" and version " >= 8.0 < 8.0.39"
-
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
>= 8.5.0 < 8.5.7
Search vendor "Apache" for product "Tomcat" and version " >= 8.5.0 < 8.5.7"
-
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
9.0.0
Search vendor "Apache" for product "Tomcat" and version "9.0.0"
-
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
9.0.0
Search vendor "Apache" for product "Tomcat" and version "9.0.0"
milestone1
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
9.0.0
Search vendor "Apache" for product "Tomcat" and version "9.0.0"
milestone10
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
9.0.0
Search vendor "Apache" for product "Tomcat" and version "9.0.0"
milestone11
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
9.0.0
Search vendor "Apache" for product "Tomcat" and version "9.0.0"
milestone2
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
9.0.0
Search vendor "Apache" for product "Tomcat" and version "9.0.0"
milestone3
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
9.0.0
Search vendor "Apache" for product "Tomcat" and version "9.0.0"
milestone4
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
9.0.0
Search vendor "Apache" for product "Tomcat" and version "9.0.0"
milestone5
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
9.0.0
Search vendor "Apache" for product "Tomcat" and version "9.0.0"
milestone6
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
9.0.0
Search vendor "Apache" for product "Tomcat" and version "9.0.0"
milestone7
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
9.0.0
Search vendor "Apache" for product "Tomcat" and version "9.0.0"
milestone8
Affected
Apache
Search vendor "Apache"
Tomcat
Search vendor "Apache" for product "Tomcat"
9.0.0
Search vendor "Apache" for product "Tomcat" and version "9.0.0"
milestone9
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
16.04
Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04"
esm
Affected
Netapp
Search vendor "Netapp"
7-mode Transition Tool
Search vendor "Netapp" for product "7-mode Transition Tool"
--
Affected
Netapp
Search vendor "Netapp"
Oncommand Insight
Search vendor "Netapp" for product "Oncommand Insight"
--
Affected
Netapp
Search vendor "Netapp"
Oncommand Shift
Search vendor "Netapp" for product "Oncommand Shift"
--
Affected
Netapp
Search vendor "Netapp"
Snap Creator Framework
Search vendor "Netapp" for product "Snap Creator Framework"
--
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
8.0
Search vendor "Debian" for product "Debian Linux" and version "8.0"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Web Server
Search vendor "Redhat" for product "Jboss Enterprise Web Server"
3.0.0
Search vendor "Redhat" for product "Jboss Enterprise Web Server" and version "3.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Agile Engineering Data Management
Search vendor "Oracle" for product "Agile Engineering Data Management"
6.1.3
Search vendor "Oracle" for product "Agile Engineering Data Management" and version "6.1.3"
-
Affected
Oracle
Search vendor "Oracle"
Agile Engineering Data Management
Search vendor "Oracle" for product "Agile Engineering Data Management"
6.2.0
Search vendor "Oracle" for product "Agile Engineering Data Management" and version "6.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Agile Engineering Data Management
Search vendor "Oracle" for product "Agile Engineering Data Management"
6.2.1.0
Search vendor "Oracle" for product "Agile Engineering Data Management" and version "6.2.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Agile Plm
Search vendor "Oracle" for product "Agile Plm"
9.3.5
Search vendor "Oracle" for product "Agile Plm" and version "9.3.5"
-
Affected
Oracle
Search vendor "Oracle"
Agile Plm
Search vendor "Oracle" for product "Agile Plm"
9.3.6
Search vendor "Oracle" for product "Agile Plm" and version "9.3.6"
-
Affected
Oracle
Search vendor "Oracle"
Communications Application Session Controller
Search vendor "Oracle" for product "Communications Application Session Controller"
3.7.1
Search vendor "Oracle" for product "Communications Application Session Controller" and version "3.7.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Application Session Controller
Search vendor "Oracle" for product "Communications Application Session Controller"
3.8.0
Search vendor "Oracle" for product "Communications Application Session Controller" and version "3.8.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Instant Messaging Server
Search vendor "Oracle" for product "Communications Instant Messaging Server"
10.0.1
Search vendor "Oracle" for product "Communications Instant Messaging Server" and version "10.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Interactive Session Recorder
Search vendor "Oracle" for product "Communications Interactive Session Recorder"
6.0
Search vendor "Oracle" for product "Communications Interactive Session Recorder" and version "6.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Interactive Session Recorder
Search vendor "Oracle" for product "Communications Interactive Session Recorder"
6.1
Search vendor "Oracle" for product "Communications Interactive Session Recorder" and version "6.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Interactive Session Recorder
Search vendor "Oracle" for product "Communications Interactive Session Recorder"
6.2
Search vendor "Oracle" for product "Communications Interactive Session Recorder" and version "6.2"
-
Affected
Oracle
Search vendor "Oracle"
Hospitality Guest Access
Search vendor "Oracle" for product "Hospitality Guest Access"
4.2.0
Search vendor "Oracle" for product "Hospitality Guest Access" and version "4.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Hospitality Guest Access
Search vendor "Oracle" for product "Hospitality Guest Access"
4.2.1
Search vendor "Oracle" for product "Hospitality Guest Access" and version "4.2.1"
-
Affected
Oracle
Search vendor "Oracle"
Micros Relate Crm Software
Search vendor "Oracle" for product "Micros Relate Crm Software"
10.8
Search vendor "Oracle" for product "Micros Relate Crm Software" and version "10.8"
-
Affected
Oracle
Search vendor "Oracle"
Micros Relate Crm Software
Search vendor "Oracle" for product "Micros Relate Crm Software"
11.4
Search vendor "Oracle" for product "Micros Relate Crm Software" and version "11.4"
-
Affected
Oracle
Search vendor "Oracle"
Micros Retail Xbri Loss Prevention
Search vendor "Oracle" for product "Micros Retail Xbri Loss Prevention"
10.0.1
Search vendor "Oracle" for product "Micros Retail Xbri Loss Prevention" and version "10.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Micros Retail Xbri Loss Prevention
Search vendor "Oracle" for product "Micros Retail Xbri Loss Prevention"
10.5.0
Search vendor "Oracle" for product "Micros Retail Xbri Loss Prevention" and version "10.5.0"
-
Affected
Oracle
Search vendor "Oracle"
Micros Retail Xbri Loss Prevention
Search vendor "Oracle" for product "Micros Retail Xbri Loss Prevention"
10.6.0
Search vendor "Oracle" for product "Micros Retail Xbri Loss Prevention" and version "10.6.0"
-
Affected
Oracle
Search vendor "Oracle"
Micros Retail Xbri Loss Prevention
Search vendor "Oracle" for product "Micros Retail Xbri Loss Prevention"
10.7.7
Search vendor "Oracle" for product "Micros Retail Xbri Loss Prevention" and version "10.7.7"
-
Affected
Oracle
Search vendor "Oracle"
Micros Retail Xbri Loss Prevention
Search vendor "Oracle" for product "Micros Retail Xbri Loss Prevention"
10.8.0
Search vendor "Oracle" for product "Micros Retail Xbri Loss Prevention" and version "10.8.0"
-
Affected
Oracle
Search vendor "Oracle"
Micros Retail Xbri Loss Prevention
Search vendor "Oracle" for product "Micros Retail Xbri Loss Prevention"
10.8.1
Search vendor "Oracle" for product "Micros Retail Xbri Loss Prevention" and version "10.8.1"
-
Affected
Oracle
Search vendor "Oracle"
Mysql Enterprise Monitor
Search vendor "Oracle" for product "Mysql Enterprise Monitor"
<= 3.2.8.2223
Search vendor "Oracle" for product "Mysql Enterprise Monitor" and version " <= 3.2.8.2223"
-
Affected
Oracle
Search vendor "Oracle"
Mysql Enterprise Monitor
Search vendor "Oracle" for product "Mysql Enterprise Monitor"
>= 3.3.0 <= 3.3.4.3247
Search vendor "Oracle" for product "Mysql Enterprise Monitor" and version " >= 3.3.0 <= 3.3.4.3247"
-
Affected
Oracle
Search vendor "Oracle"
Mysql Enterprise Monitor
Search vendor "Oracle" for product "Mysql Enterprise Monitor"
>= 3.4.0 <= 3.4.2.4181
Search vendor "Oracle" for product "Mysql Enterprise Monitor" and version " >= 3.4.0 <= 3.4.2.4181"
-
Affected
Oracle
Search vendor "Oracle"
Retail Convenience And Fuel Pos Software
Search vendor "Oracle" for product "Retail Convenience And Fuel Pos Software"
2.1.132
Search vendor "Oracle" for product "Retail Convenience And Fuel Pos Software" and version "2.1.132"
-
Affected
Oracle
Search vendor "Oracle"
Transportation Management
Search vendor "Oracle" for product "Transportation Management"
6.3.0
Search vendor "Oracle" for product "Transportation Management" and version "6.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Transportation Management
Search vendor "Oracle" for product "Transportation Management"
6.3.1
Search vendor "Oracle" for product "Transportation Management" and version "6.3.1"
-
Affected
Oracle
Search vendor "Oracle"
Transportation Management
Search vendor "Oracle" for product "Transportation Management"
6.3.2
Search vendor "Oracle" for product "Transportation Management" and version "6.3.2"
-
Affected
Oracle
Search vendor "Oracle"
Transportation Management
Search vendor "Oracle" for product "Transportation Management"
6.3.3
Search vendor "Oracle" for product "Transportation Management" and version "6.3.3"
-
Affected
Oracle
Search vendor "Oracle"
Transportation Management
Search vendor "Oracle" for product "Transportation Management"
6.3.4
Search vendor "Oracle" for product "Transportation Management" and version "6.3.4"
-
Affected
Oracle
Search vendor "Oracle"
Transportation Management
Search vendor "Oracle" for product "Transportation Management"
6.3.5
Search vendor "Oracle" for product "Transportation Management" and version "6.3.5"
-
Affected
Oracle
Search vendor "Oracle"
Transportation Management
Search vendor "Oracle" for product "Transportation Management"
6.3.6
Search vendor "Oracle" for product "Transportation Management" and version "6.3.6"
-
Affected
Oracle
Search vendor "Oracle"
Transportation Management
Search vendor "Oracle" for product "Transportation Management"
6.3.7
Search vendor "Oracle" for product "Transportation Management" and version "6.3.7"
-
Affected