CVE-2016-8735: Apache Tomcat Remote Code Execution Vulnerability
Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types. Required action: Apply updates per vendor instructions.
· high severity · unattributed attribution
Evidence and provenance
- Original source
- CISA KEV report ↗
- Published
- 2023-05-12T00:00:00Z
- Confidence basis
- No actor match
- Record ID
75d1ec7e42acf0fa705b
Vulnerabilities
CVE-2016-3427, CVE-2016-8735
Use and citation
Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.