CVE-2016-8735Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
CWE-284 · Improper access control
Exploited in the wild
Confirmed real-world exploitation.
CVSS E:A
| Index | Artifact | Stars | First seen |
|---|---|---|---|
| Nuclei | Apache Tomcat - Remote Code Execution via JMX Ports |
A Waratek agent blocks this today.
Applicable rule: A researcher classified this CVE as MITIGATED-BY-SECURE-RULE, protected by the ARMR Deserial RCE rule.
| Decided by | manual-classification : A researcher's recorded decision for this specific CVE |
|---|---|
| Finding | A researcher classified this CVE as MITIGATED-BY-SECURE-RULE, protected by the ARMR Deserial RCE rule. |
Written by a Waratek engineer reviewing this CVE. A written classification sets the status directly, ahead of every automated scope rule except a withdrawal.
Rule Name: Deserial RCE rule
The ARMR Deserial RCE rule blocks the RCE: attackers exploit JmxRemoteLifecycleListener by sending a serialized gadget payload in place of JMX credentials, triggering ObjectInputStream.readObject() during RMI authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
3 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
NVD | Primary | published |
| CVSS 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CISA-ADP | Secondary | |
| CVSS 2.0 | 7.5 | no band published | AV:N/AC:L/Au:N/C:P/I:P/A:P |
NVD | Primary |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update October 2017 ↗ | CPU | 2017-Q4 | Oracle Database Server / WLM (Apache Tomcat) (12.2.0.1) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Database Server | WLM (Apache Tomcat) | 12.2.0.1 | 12.2.0.1 |
| Package Coordinate | Introduced | Fixed | Last affected |
|---|---|---|---|
org.apache.tomcat:tomcat-catalina-jmx-remote |
0 | 6.0.48 |
unbounded |
org.apache.tomcat:tomcat-catalina-jmx-remote |
7.0.0 | 7.0.73 |
unbounded |
org.apache.tomcat:tomcat-catalina-jmx-remote |
8.0.0 | 8.0.39 |
unbounded |
org.apache.tomcat:tomcat-catalina-jmx-remote |
8.5.0 | 8.5.7 |
unbounded |
org.apache.tomcat:tomcat-catalina-jmx-remote |
9.0.0.M1 | 9.0.0.M12 |
unbounded |
org.apache.tomcat:tomcat-catalina |
0 | 6.0.48 |
unbounded |
org.apache.tomcat:tomcat-catalina |
7.0.0 | 7.0.73 |
unbounded |
org.apache.tomcat:tomcat-catalina |
8.0.0 | 8.0.39 |
unbounded |
org.apache.tomcat:tomcat-catalina |
8.5.0 | 8.5.7 |
unbounded |
org.apache.tomcat:tomcat-catalina |
9.0.0.M1 | 9.0.0.M12 |
unbounded |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | apache | tomcat | generic | < 6.0.48 · ≥ 7.0.0 and < 7.0.73 · ≥ 8.0 and < 8.0.39 · ≥ 8.5.0 and < 8.5.7 · 9.0.0 · 9.0.0:milestone1 · 9.0.0:milestone10 · 9.0.0:milestone11 · 9.0.0:milestone2 · 9.0.0:milestone3 · 9.0.0:milestone4 · 9.0.0:milestone5 · 9.0.0:milestone6 · 9.0.0:milestone7 · 9.0.0:milestone8 · 9.0.0:milestone9 |
| nvd | canonical | ubuntu linux | generic | 16.04 |
| nvd | debian | debian linux | generic | 8.0 |
| nvd | netapp | 7-mode transition tool | generic | any version |
| nvd | netapp | oncommand insight | generic | any version |
| nvd | netapp | oncommand shift | generic | any version |
| nvd | netapp | snap creator framework | generic | any version |
| nvd | oracle | agile engineering data management | generic | 6.1.3 · 6.2.0 · 6.2.1.0 |
| nvd | oracle | agile product lifecycle management | generic | 9.3.5 · 9.3.6 |
| nvd | oracle | communications application session controller | generic | 3.7.1 · 3.8.0 |
| nvd | oracle | communications instant messaging server | generic | 10.0.1 |
| nvd | oracle | communications interactive session recorder | generic | 6.0 · 6.1 · 6.2 |
| nvd | oracle | hospitality guest access | generic | 4.2.0 · 4.2.1 |
| nvd | oracle | micros relate crm software | generic | 10.8 · 11.4 |
| nvd | oracle | micros retail xbri loss prevention | generic | 10.0.1 · 10.5.0 · 10.6.0 · 10.7.7 · 10.8.0 · 10.8.1 |
| nvd | oracle | mysql enterprise monitor | generic | ≤ 3.2.8.2223 · ≥ 3.3.0 and ≤ 3.3.4.3247 · ≥ 3.4.0 and ≤ 3.4.2.4181 |
| nvd | oracle | retail convenience and fuel pos software | generic | 2.1.132 |
| nvd | oracle | transportation management | generic | 6.3.0 · 6.3.1 · 6.3.2 · 6.3.3 · 6.3.4 · 6.3.5 · 6.3.6 · 6.3.7 |
| osv | org.apache.tomcat | tomcat-catalina | generic | < 6.0.48 · ≥ 7.0.0 and < 7.0.73 · ≥ 8.0.0 and < 8.0.39 · ≥ 8.5.0 and < 8.5.7 · ≥ 9.0.0 and < 9.0.0 |
| osv | org.apache.tomcat | tomcat-catalina-jmx-remote | generic | < 6.0.48 · ≥ 7.0.0 and < 7.0.73 · ≥ 8.0.0 and < 8.0.39 · ≥ 8.5.0 and < 8.5.7 · ≥ 9.0.0 and < 9.0.0 |
| nvd | redhat | jboss enterprise web server | generic | 3.0.0 |
| Published | 2017-04-06 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-08-25 | NVD's own last-modified date for this record. |
| Classification created | 2026-09-14 | First commit adding this CVE's research note. |
| Last VRT activity | 2026-09-14 | Most recent commit touching this CVE's classification, patch or rule file. |