Threat intelligence report · CISA KEV

CVE-2016-8735: Apache Tomcat Remote Code Execution Vulnerability

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types. Required action: Apply updates per vendor instructions.

· high severity · unattributed attribution

Evidence and provenance

Original source
CISA KEV report ↗
Published
2023-05-12T00:00:00Z
Confidence basis
No actor match
Record ID
75d1ec7e42acf0fa705b

Vulnerabilities

CVE-2016-3427, CVE-2016-8735

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.