CVE-2016-8735
KEVmassUnauthenticated RCE in Apache Tomcat via JmxRemoteLifecycleListener
CISA: Apache Tomcat Remote Code Execution Vulnerability
CVE-2016-8735 is a remote code execution flaw in Apache Tomcat's bundled JmxRemoteLifecycleListener, which was not updated for consistency with Oracle's patch for the related JMX issue CVE-2016-3427, leaving its credential handling insecure. The flaw can be triggered only when this listener is in use and an attacker can reach the server's JMX ports over the network; no authentication or user interaction is required (CVSS 9.8). Successful exploitation lets an attacker execute arbitrary code in the context of the Tomcat process. It affects Tomcat versions before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12, as well as Tomcat-containing products from Canonical, Debian, Red Hat, NetApp, and Oracle. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-05-12, indicating observed exploitation in the wild, and EPSS assigns a roughly 90% probability of exploitation within 30 days (99th percentile), although no public PoC is known.
What to do: Upgrade Tomcat to 6.0.48, 7.0.73, 8.0.39, 8.5.7, or 9.0.0.M12 or later, or apply vendor-patched packages/deliverables from Canonical, Debian, Red Hat, NetApp, or Oracle, per CISA's required action. Where upgrades are not immediate, remove or disable the JmxRemoteLifecycleListener or firewall the JMX ports so they are unreachable from untrusted networks. Inventory all Tomcat instances and Tomcat-embedding products (NetApp, Red Hat JBoss EWS, Oracle, distro packages) and confirm whether the JMX remote listener is enabled and exposed; ransomware use is unknown but KEV listing mandates patching by the required due date.
| Apache Tomcat | before 6.0.48; 7.x before 7.0.73; 8.x before 8.0.39; 8.5.x before 8.5.7; 9.x before 9.0.0.M12 (only when JmxRemoteLifecycleListener is used and JMX ports are re |
| Canonical Ubuntu Linux | — |
| Debian Linux | — |
| Red Hat JBoss Enterprise Web Server | — |
| NetApp 7-Mode Transition Tool | — |
| NetApp OnCommand Insight | — |
| NetApp OnCommand Shift | — |
| NetApp Snap Creator Framework | — |
| Oracle Agile Engineering Data Management | — |
| Oracle Agile Product Lifecycle Management | — |
| Oracle Communications Application Session Controller | — |
| Oracle Communications Instant Messaging Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
- Affected
- Apache Tomcat
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apachecanonicalnetappdebianredhatoracle
- Products
- tomcat, ubuntu linux, 7-mode transition tool, oncommand insight, oncommand shift, snap creator framework, debian linux, jboss enterprise web server, agile engineering data management, agile product lifecycle management, communications application session controller, communications instant messaging server
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H