CVE-2016-8735
Apache Tomcat Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 2 June 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 90.34% probability · 100th percentile
- CISA KEV
- Listed 12 May 2023 · due 2 June 2023
- Affected
- apache/tomcat · canonical/ubuntu linux · netapp/7-mode transition tool · netapp/oncommand insight · netapp/oncommand shift · netapp/snap creator framework · debian/debian linux · redhat/jboss enterprise web server · oracle/agile engineering data management · oracle/agile product lifecycle management · oracle/communications application session controller · oracle/communications instant messaging server · oracle/communications interactive session recorder · oracle/hospitality guest access · oracle/micros relate crm software · oracle/micros retail xbri loss prevention · oracle/mysql enterprise monitor · oracle/retail convenience and fuel pos software · oracle/transportation management
- Source
- security@apache.org
CISA notes
Apply updates per vendor instructions. https://tomcat.apache.org/security-9.html; https://nvd.nist.gov/vuln/detail/CVE-2016-8735
References
- http://rhn.redhat.com/errata/RHSA-2017-0457.htmlThird Party Advisory
- http://seclists.org/oss-sec/2016/q4/502Mailing List, Mitigation, Third Party Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1767644Broken Link, Patch
- http://svn.apache.org/viewvc?view=revision&revision=1767656Broken Link, Patch
- http://svn.apache.org/viewvc?view=revision&revision=1767676Broken Link, Patch
- http://svn.apache.org/viewvc?view=revision&revision=1767684Broken Link, Patch
- http://tomcat.apache.org/security-6.htmlRelease Notes, Vendor Advisory
- http://tomcat.apache.org/security-7.htmlRelease Notes, Vendor Advisory
- http://tomcat.apache.org/security-8.htmlRelease Notes, Vendor Advisory
- http://tomcat.apache.org/security-9.htmlRelease Notes, Vendor Advisory
- http://www.debian.org/security/2016/dsa-3738Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/94463Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037331Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:0455Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:0456Third Party Advisory
- https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.