First published: Tue Nov 22 2016(Updated: )
Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.
Credit: security@apache.org security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tomcat | =6.0.0 | |
Apache Tomcat | =6.0.1 | |
Apache Tomcat | =6.0.2 | |
Apache Tomcat | =6.0.3 | |
Apache Tomcat | =6.0.4 | |
Apache Tomcat | =6.0.5 | |
Apache Tomcat | =6.0.6 | |
Apache Tomcat | =6.0.7 | |
Apache Tomcat | =6.0.8 | |
Apache Tomcat | =6.0.9 | |
Apache Tomcat | =6.0.10 | |
Apache Tomcat | =6.0.11 | |
Apache Tomcat | =6.0.12 | |
Apache Tomcat | =6.0.13 | |
Apache Tomcat | =6.0.14 | |
Apache Tomcat | =6.0.15 | |
Apache Tomcat | =6.0.16 | |
Apache Tomcat | =6.0.17 | |
Apache Tomcat | =6.0.18 | |
Apache Tomcat | =6.0.19 | |
Apache Tomcat | =6.0.20 | |
Apache Tomcat | =6.0.21 | |
Apache Tomcat | =6.0.22 | |
Apache Tomcat | =6.0.23 | |
Apache Tomcat | =6.0.24 | |
Apache Tomcat | =6.0.25 | |
Apache Tomcat | =6.0.26 | |
Apache Tomcat | =6.0.27 | |
Apache Tomcat | =6.0.28 | |
Apache Tomcat | =6.0.29 | |
Apache Tomcat | =6.0.30 | |
Apache Tomcat | =6.0.31 | |
Apache Tomcat | =6.0.32 | |
Apache Tomcat | =6.0.33 | |
Apache Tomcat | =6.0.34 | |
Apache Tomcat | =6.0.35 | |
Apache Tomcat | =6.0.36 | |
Apache Tomcat | =6.0.37 | |
Apache Tomcat | =6.0.38 | |
Apache Tomcat | =6.0.39 | |
Apache Tomcat | =6.0.40 | |
Apache Tomcat | =6.0.41 | |
Apache Tomcat | =6.0.42 | |
Apache Tomcat | =6.0.43 | |
Apache Tomcat | =6.0.44 | |
Apache Tomcat | =6.0.45 | |
Apache Tomcat | =6.0.46 | |
Apache Tomcat | =6.0.47 | |
Apache Tomcat | =7.0.0 | |
Apache Tomcat | =7.0.1 | |
Apache Tomcat | =7.0.2 | |
Apache Tomcat | =7.0.3 | |
Apache Tomcat | =7.0.4 | |
Apache Tomcat | =7.0.5 | |
Apache Tomcat | =7.0.6 | |
Apache Tomcat | =7.0.7 | |
Apache Tomcat | =7.0.8 | |
Apache Tomcat | =7.0.9 | |
Apache Tomcat | =7.0.10 | |
Apache Tomcat | =7.0.11 | |
Apache Tomcat | =7.0.12 | |
Apache Tomcat | =7.0.13 | |
Apache Tomcat | =7.0.14 | |
Apache Tomcat | =7.0.15 | |
Apache Tomcat | =7.0.16 | |
Apache Tomcat | =7.0.17 | |
Apache Tomcat | =7.0.18 | |
Apache Tomcat | =7.0.19 | |
Apache Tomcat | =7.0.20 | |
Apache Tomcat | =7.0.21 | |
Apache Tomcat | =7.0.22 | |
Apache Tomcat | =7.0.23 | |
Apache Tomcat | =7.0.24 | |
Apache Tomcat | =7.0.25 | |
Apache Tomcat | =7.0.26 | |
Apache Tomcat | =7.0.27 | |
Apache Tomcat | =7.0.28 | |
Apache Tomcat | =7.0.29 | |
Apache Tomcat | =7.0.30 | |
Apache Tomcat | =7.0.31 | |
Apache Tomcat | =7.0.32 | |
Apache Tomcat | =7.0.33 | |
Apache Tomcat | =7.0.34 | |
Apache Tomcat | =7.0.35 | |
Apache Tomcat | =7.0.36 | |
Apache Tomcat | =7.0.37 | |
Apache Tomcat | =7.0.38 | |
Apache Tomcat | =7.0.39 | |
Apache Tomcat | =7.0.40 | |
Apache Tomcat | =7.0.41 | |
Apache Tomcat | =7.0.42 | |
Apache Tomcat | =7.0.43 | |
Apache Tomcat | =7.0.44 | |
Apache Tomcat | =7.0.45 | |
Apache Tomcat | =7.0.46 | |
Apache Tomcat | =7.0.47 | |
Apache Tomcat | =7.0.48 | |
Apache Tomcat | =7.0.49 | |
Apache Tomcat | =7.0.50 | |
Apache Tomcat | =7.0.51 | |
Apache Tomcat | =7.0.52 | |
Apache Tomcat | =7.0.53 | |
Apache Tomcat | =7.0.54 | |
Apache Tomcat | =7.0.55 | |
Apache Tomcat | =7.0.56 | |
Apache Tomcat | =7.0.57 | |
Apache Tomcat | =7.0.58 | |
Apache Tomcat | =7.0.59 | |
Apache Tomcat | =7.0.60 | |
Apache Tomcat | =7.0.61 | |
Apache Tomcat | =7.0.62 | |
Apache Tomcat | =7.0.63 | |
Apache Tomcat | =7.0.64 | |
Apache Tomcat | =7.0.65 | |
Apache Tomcat | =7.0.66 | |
Apache Tomcat | =7.0.67 | |
Apache Tomcat | =7.0.68 | |
Apache Tomcat | =7.0.69 | |
Apache Tomcat | =7.0.70 | |
Apache Tomcat | =7.0.71 | |
Apache Tomcat | =7.0.72 | |
Apache Tomcat | =8.0.0 | |
Apache Tomcat | =8.0.1 | |
Apache Tomcat | =8.0.2 | |
Apache Tomcat | =8.0.3 | |
Apache Tomcat | =8.0.4 | |
Apache Tomcat | =8.0.5 | |
Apache Tomcat | =8.0.6 | |
Apache Tomcat | =8.0.7 | |
Apache Tomcat | =8.0.8 | |
Apache Tomcat | =8.0.9 | |
Apache Tomcat | =8.0.10 | |
Apache Tomcat | =8.0.11 | |
Apache Tomcat | =8.0.12 | |
Apache Tomcat | =8.0.13 | |
Apache Tomcat | =8.0.14 | |
Apache Tomcat | =8.0.15 | |
Apache Tomcat | =8.0.16 | |
Apache Tomcat | =8.0.17 | |
Apache Tomcat | =8.0.18 | |
Apache Tomcat | =8.0.19 | |
Apache Tomcat | =8.0.20 | |
Apache Tomcat | =8.0.21 | |
Apache Tomcat | =8.0.22 | |
Apache Tomcat | =8.0.23 | |
Apache Tomcat | =8.0.24 | |
Apache Tomcat | =8.0.25 | |
Apache Tomcat | =8.0.26 | |
Apache Tomcat | =8.0.27 | |
Apache Tomcat | =8.0.28 | |
Apache Tomcat | =8.0.29 | |
Apache Tomcat | =8.0.30 | |
Apache Tomcat | =8.0.31 | |
Apache Tomcat | =8.0.32 | |
Apache Tomcat | =8.0.33 | |
Apache Tomcat | =8.0.34 | |
Apache Tomcat | =8.0.35 | |
Apache Tomcat | =8.0.36 | |
Apache Tomcat | =8.0.37 | |
Apache Tomcat | =8.0.38 | |
Apache Tomcat | =8.5.0 | |
Apache Tomcat | =8.5.1 | |
Apache Tomcat | =8.5.2 | |
Apache Tomcat | =8.5.3 | |
Apache Tomcat | =8.5.4 | |
Apache Tomcat | =8.5.5 | |
Apache Tomcat | =8.5.6 | |
Apache Tomcat | =9.0.0-m1 | |
Apache Tomcat | =9.0.0-m10 | |
Apache Tomcat | =9.0.0-m11 | |
Apache Tomcat | =9.0.0-m2 | |
Apache Tomcat | =9.0.0-m3 | |
Apache Tomcat | =9.0.0-m4 | |
Apache Tomcat | =9.0.0-m5 | |
Apache Tomcat | =9.0.0-m6 | |
Apache Tomcat | =9.0.0-m7 | |
Apache Tomcat | =9.0.0-m8 | |
Apache Tomcat | =9.0.0-m9 | |
redhat/tomcat | <6.0.48 | 6.0.48 |
redhat/tomcat | <7.0.73 | 7.0.73 |
redhat/tomcat | <8.0.39 | 8.0.39 |
redhat/tomcat | <8.5.8 | 8.5.8 |
maven/org.apache.tomcat:tomcat-catalina-jmx-remote | >=9.0.0.M1<9.0.0.M12 | 9.0.0.M12 |
maven/org.apache.tomcat:tomcat-catalina-jmx-remote | >=8.5.0<8.5.7 | 8.5.7 |
maven/org.apache.tomcat:tomcat-catalina-jmx-remote | >=8.0.0<8.0.39 | 8.0.39 |
maven/org.apache.tomcat:tomcat-catalina-jmx-remote | >=7.0.0<7.0.73 | 7.0.73 |
maven/org.apache.tomcat:tomcat-catalina-jmx-remote | <6.0.48 | 6.0.48 |
maven/org.apache.tomcat:tomcat-catalina | >=9.0.0.M1<9.0.0.M12 | 9.0.0.M12 |
maven/org.apache.tomcat:tomcat-catalina | >=8.5.0<8.5.7 | 8.5.7 |
maven/org.apache.tomcat:tomcat-catalina | >=8.0.0<8.0.39 | 8.0.39 |
maven/org.apache.tomcat:tomcat-catalina | >=7.0.0<7.0.73 | 7.0.73 |
maven/org.apache.tomcat:tomcat-catalina | <6.0.48 | 6.0.48 |
Apache Tomcat | ||
debian/tomcat9 | 9.0.43-2~deb11u10 9.0.43-2~deb11u11 9.0.70-2 9.0.95-1 | |
Apache Tomcat | <6.0.48 | |
Apache Tomcat | >=7.0.0<7.0.73 | |
Apache Tomcat | >=8.0<8.0.39 | |
Apache Tomcat | >=8.5.0<8.5.7 | |
Apache Tomcat | =9.0.0 | |
Apache Tomcat | =9.0.0-milestone1 | |
Apache Tomcat | =9.0.0-milestone10 | |
Apache Tomcat | =9.0.0-milestone11 | |
Apache Tomcat | =9.0.0-milestone2 | |
Apache Tomcat | =9.0.0-milestone3 | |
Apache Tomcat | =9.0.0-milestone4 | |
Apache Tomcat | =9.0.0-milestone5 | |
Apache Tomcat | =9.0.0-milestone6 | |
Apache Tomcat | =9.0.0-milestone7 | |
Apache Tomcat | =9.0.0-milestone8 | |
Apache Tomcat | =9.0.0-milestone9 | |
Ubuntu | =16.04 | |
NetApp 7-Mode Transition Tool | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Shift | ||
NetApp Snap Creator Framework | ||
Debian | =8.0 | |
Red Hat JBoss Enterprise Web Server | =3.0.0 | |
Oracle Agile Engineering Data Management | =6.1.3 | |
Oracle Agile Engineering Data Management | =6.2.0 | |
Oracle Agile Engineering Data Management | =6.2.1.0 | |
Oracle Agile PLM | =9.3.5 | |
Oracle Agile PLM | =9.3.6 | |
Oracle Communications Application Session Controller | =3.7.1 | |
Oracle Communications Application Session Controller | =3.8.0 | |
Oracle Communications Instant Messaging Server | =10.0.1 | |
Oracle Communications Interactive Session Recorder | =6.0 | |
Oracle Communications Interactive Session Recorder | =6.1 | |
Oracle Communications Interactive Session Recorder | =6.2 | |
Oracle Hospitality Guest Access | =4.2.0 | |
Oracle Hospitality Guest Access | =4.2.1 | |
Oracle Micros Relate Customer Relationship Management Software | =10.8 | |
Oracle Micros Relate Customer Relationship Management Software | =11.4 | |
Oracle MICROS Retail XBRi Loss Prevention | =10.0.1 | |
Oracle MICROS Retail XBRi Loss Prevention | =10.5.0 | |
Oracle MICROS Retail XBRi Loss Prevention | =10.6.0 | |
Oracle MICROS Retail XBRi Loss Prevention | =10.7.7 | |
Oracle MICROS Retail XBRi Loss Prevention | =10.8.0 | |
Oracle MICROS Retail XBRi Loss Prevention | =10.8.1 | |
MySQL Enterprise Monitor | <=3.2.8.2223 | |
MySQL Enterprise Monitor | >=3.3.0<=3.3.4.3247 | |
MySQL Enterprise Monitor | >=3.4.0<=3.4.2.4181 | |
Oracle Retail Convenience and Fuel POS Software | =2.1.132 | |
Oracle Transportation Management | =6.3.0 | |
Oracle Transportation Management | =6.3.1 | |
Oracle Transportation Management | =6.3.2 | |
Oracle Transportation Management | =6.3.3 | |
Oracle Transportation Management | =6.3.4 | |
Oracle Transportation Management | =6.3.5 | |
Oracle Transportation Management | =6.3.6 | |
Oracle Transportation Management | =6.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8735 has been rated as critical due to its potential for remote code execution.
To mitigate CVE-2016-8735, upgrade Apache Tomcat to version 6.0.48 or later, or apply necessary security patches.
CVE-2016-8735 affects Apache Tomcat versions from 6.0.0 to 6.0.47, as well as multiple versions of 7.x, 8.x, and 9.x.
The attack vector for CVE-2016-8735 involves an attacker gaining access to JMX ports exposed by the JmxRemoteLifecycleListener.
CVE-2016-8735 is associated with remote code execution vulnerabilities related to improper handling of management extensions in Apache Tomcat.