Skip to content
COOEY

EXPOSURES › CVE-2016-8735

CVE-2016-8735

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-05-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-8735 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Apache Tomcat remote code execution vulnerability exposed

Apache Tomcat contains a remote code execution vulnerability that allows attackers to execute arbitrary code if JmxRemoteLifecycleListener is used and JMX ports are accessible. This vulnerability is actively exploited and has a high embarrassment score due to the potential for significant security risks if not patched.

Shame score — Active exploitation and high potential for remote code execution

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.

AFFECTED FEDRAMP PRODUCTS · 11
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Cloud Insights
NetApp
In Process
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized