CVE-2016-8735

CRITICALCVSS 9.8/10Actively ExploitedEPSS 90.34%

Last modified

CVE-2016-8735 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.. CISA has confirmed active exploitation in the wild. EPSS estimates a 90.34% chance of exploitation in the next 30 days.

Description

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
90.34%

99.8th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Affected Software

VendorProductVersions
ApacheTomcat< 6.0.48
ApacheTomcat>= 7.0.0, < 7.0.73
ApacheTomcat>= 8.0, < 8.0.39
ApacheTomcat>= 8.5.0, < 8.5.7
ApacheTomcat9.0.0
CanonicalUbuntu Linux16.04
Netapp7-Mode Transition ToolAll versions
NetappOncommand InsightAll versions
NetappOncommand ShiftAll versions
NetappSnap Creator FrameworkAll versions
DebianDebian Linux8.0
RedhatJboss Enterprise Web Server3.0.0
OracleAgile Engineering Data Management6.1.3
OracleAgile Engineering Data Management6.2.0
OracleAgile Engineering Data Management6.2.1.0
OracleAgile Plm9.3.5
OracleAgile Plm9.3.6
OracleCommunications Application Session Controller3.7.1
OracleCommunications Application Session Controller3.8.0
OracleCommunications Instant Messaging Server10.0.1
OracleCommunications Interactive Session Recorder6.0
OracleCommunications Interactive Session Recorder6.1
OracleCommunications Interactive Session Recorder6.2
OracleHospitality Guest Access4.2.0
OracleHospitality Guest Access4.2.1
OracleMicros Relate Crm Software10.8
OracleMicros Relate Crm Software11.4
OracleMicros Retail Xbri Loss Prevention10.0.1
OracleMicros Retail Xbri Loss Prevention10.5.0
OracleMicros Retail Xbri Loss Prevention10.6.0
OracleMicros Retail Xbri Loss Prevention10.7.7
OracleMicros Retail Xbri Loss Prevention10.8.0
OracleMicros Retail Xbri Loss Prevention10.8.1
OracleMysql Enterprise Monitor<= 3.2.8.2223
OracleMysql Enterprise Monitor>= 3.3.0, <= 3.3.4.3247
OracleMysql Enterprise Monitor>= 3.4.0, <= 3.4.2.4181
OracleRetail Convenience And Fuel Pos Software2.1.132
OracleTransportation Management6.3.0
OracleTransportation Management6.3.1
OracleTransportation Management6.3.2
OracleTransportation Management6.3.3
OracleTransportation Management6.3.4
OracleTransportation Management6.3.5
OracleTransportation Management6.3.6
OracleTransportation Management6.3.7

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2016-8735?
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
How severe is CVE-2016-8735?
CVE-2016-8735 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 90.34% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2016-8735?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-8735?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST