CVE-2016-8735
Summary
| CVE | CVE-2016-8735 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-04-06 21:59:00 UTC |
| Updated | 2026-04-21 17:03:44 UTC |
| Description | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.903380000 probability, percentile 0.997870000 (date 2026-07-21)
CISA KEV: Listed on 2023-05-12; due 2023-06-02; ransomware use Unknown
Problem Types: NVD-CWE-noinfo | Remote code execution | CWE-noinfo Not enough information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
CISA Known Exploited Vulnerability
| Vendor | Apache |
|---|---|
| Product | Tomcat |
| Name | Apache Tomcat Remote Code Execution Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://tomcat.apache.org/security-9.html; https://nvd.nist.gov/vuln/detail/CVE-2016-8735 |
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Tomcat | affected before 6.0.48 | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 7.x before 7.0.73 | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 8.x before 8.0.39 | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 8.5.x before 8.5.7 | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 9.x before 9.0.0.M12 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Patch |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Oracle Critical Patch Update - July 2019 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Apache Tomcat® - Apache Tomcat 8 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Release Notes, Vendor Advisory |
| Apache Tomcat JmxRemoteLifecycleListener Bug Lets Remote Users Execute Arbitrary Code on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Patch |
| USN-4557-1: Tomcat vulnerabilities | Ubuntu security notices | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | Third Party Advisory |
| Apache Tomcat® - Apache Tomcat 7 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Release Notes, Vendor Advisory |
| [Apache-SVN] Revision 1767676 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | Broken Link, Patch |
| [Apache-SVN] Revision 1767656 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | Broken Link, Patch |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Patch |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Patch |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Patch |
| Oracle Critical Patch Update - October 2017 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Patch |
| Apache Tomcat CVE-2016-8735 Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| Oracle Critical Patch Update - January 2018 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Patch |
| [Apache-SVN] Revision 1767684 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | Broken Link, Patch |
| [Apache-SVN] Revision 1767644 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | Broken Link, Patch |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Patch |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Patch |
| oss-sec: [SECURITY] CVE-2016-8735 Apache Tomcat Remote Code Execution | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Mailing List, Mitigation, Third Party Advisory |
| Apache Tomcat® - Apache Tomcat 6 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Release Notes, Vendor Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Patch |
| Oracle Critical Patch Update Advisory - April 2019 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| CPU July 2018 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Patch |
| November 2016 Apache Tomcat Vulnerabilities in NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Third Party Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Apache Tomcat - Apache Tomcat 8 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Release Notes, Vendor Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Patch |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Patch |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Patch |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| Debian -- Security Information -- DSA-3738-1 tomcat7 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Mailing List, Third Party Advisory |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2023-05-12T00:00:00.000Z | CVE-2016-8735 added to CISA KEV |
Legacy QID Mappings
- 996852 Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-cw54-59pw-4g8c)