Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
History
No history.
Information
Published : 2017-04-06 21:59
Updated : 2025-10-22 00:15
NVD link : CVE-2016-8735
Mitre link : CVE-2016-8735
CVE.ORG link : CVE-2016-8735
JSON object : View
Products Affected
netapp
- 7-mode_transition_tool
- oncommand_insight
- snap_creator_framework
- oncommand_shift
oracle
- communications_interactive_session_recorder
- communications_application_session_controller
- agile_plm
- retail_convenience_and_fuel_pos_software
- transportation_management
- micros_relate_crm_software
- agile_engineering_data_management
- mysql_enterprise_monitor
- hospitality_guest_access
- micros_retail_xbri_loss_prevention
- communications_instant_messaging_server
redhat
- jboss_enterprise_web_server
debian
- debian_linux
canonical
- ubuntu_linux
apache
- tomcat
CWE
