ZeroHour

CVE-2016-8735

KEVmass

Unauthenticated RCE in Apache Tomcat via JmxRemoteLifecycleListener

CISA: Apache Tomcat Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
90%p100
Published
()
KEV added
AI analysis

CVE-2016-8735 is a remote code execution flaw in Apache Tomcat's bundled JmxRemoteLifecycleListener, which was not updated for consistency with Oracle's patch for the related JMX issue CVE-2016-3427, leaving its credential handling insecure. The flaw can be triggered only when this listener is in use and an attacker can reach the server's JMX ports over the network; no authentication or user interaction is required (CVSS 9.8). Successful exploitation lets an attacker execute arbitrary code in the context of the Tomcat process. It affects Tomcat versions before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12, as well as Tomcat-containing products from Canonical, Debian, Red Hat, NetApp, and Oracle. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-05-12, indicating observed exploitation in the wild, and EPSS assigns a roughly 90% probability of exploitation within 30 days (99th percentile), although no public PoC is known.

What to do: Upgrade Tomcat to 6.0.48, 7.0.73, 8.0.39, 8.5.7, or 9.0.0.M12 or later, or apply vendor-patched packages/deliverables from Canonical, Debian, Red Hat, NetApp, or Oracle, per CISA's required action. Where upgrades are not immediate, remove or disable the JmxRemoteLifecycleListener or firewall the JMX ports so they are unreachable from untrusted networks. Inventory all Tomcat instances and Tomcat-embedding products (NetApp, Red Hat JBoss EWS, Oracle, distro packages) and confirm whether the JMX remote listener is enabled and exposed; ransomware use is unknown but KEV listing mandates patching by the required due date.

Affected
Apache Tomcatbefore 6.0.48; 7.x before 7.0.73; 8.x before 8.0.39; 8.5.x before 8.5.7; 9.x before 9.0.0.M12 (only when JmxRemoteLifecycleListener is used and JMX ports are re
Canonical Ubuntu Linux
Debian Linux
Red Hat JBoss Enterprise Web Server
NetApp 7-Mode Transition Tool
NetApp OnCommand Insight
NetApp OnCommand Shift
NetApp Snap Creator Framework
Oracle Agile Engineering Data Management
Oracle Agile Product Lifecycle Management
Oracle Communications Application Session Controller
Oracle Communications Instant Messaging Server
Estimated exposure
massmillions of Tomcat installations worldwide and hundreds of thousands of internet-exposed Tomcat instances; the plausibly vulnerable subset (JMX remote listener… — Internet-wide scans have long observed hundreds of thousands of exposed Apache Tomcat servers and Tomcat is embedded in numerous commercial and OS-packaged products, though actual exploitability is narrowed to deployments using…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

CISA Known Exploited Vulnerability
Affected
Apache Tomcat
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apachecanonicalnetappdebianredhatoracle
Products
tomcat, ubuntu linux, 7-mode transition tool, oncommand insight, oncommand shift, snap creator framework, debian linux, jboss enterprise web server, agile engineering data management, agile product lifecycle management, communications application session controller, communications instant messaging server
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news