SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2016-8735

Apache Tomcat Remote Code Execution Vulnerability

KEVCRITICAL 9.8EPSS 90.3%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 2 June 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
90.34% probability · 100th percentile
CISA KEV
Listed 12 May 2023 · due 2 June 2023
Affected
apache/tomcat · canonical/ubuntu linux · netapp/7-mode transition tool · netapp/oncommand insight · netapp/oncommand shift · netapp/snap creator framework · debian/debian linux · redhat/jboss enterprise web server · oracle/agile engineering data management · oracle/agile product lifecycle management · oracle/communications application session controller · oracle/communications instant messaging server · oracle/communications interactive session recorder · oracle/hospitality guest access · oracle/micros relate crm software · oracle/micros retail xbri loss prevention · oracle/mysql enterprise monitor · oracle/retail convenience and fuel pos software · oracle/transportation management
Source
security@apache.org

CISA notes

Apply updates per vendor instructions. https://tomcat.apache.org/security-9.html; https://nvd.nist.gov/vuln/detail/CVE-2016-8735

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.