VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 18 hours ago

CVE-2016-8735

9.8 Critical Protected by RASP

Description

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

CWE-284 · Improper access control

Exploitation Status

Exploited in the wild

Confirmed real-world exploitation.

CVSS E:A

  • CISA KEV listed Confirmed exploitation in the wild. Added 2023-05-12 · remediation due 2023-06-02 · ransomware use: unknown
  • CISA Vulnrichment exploitation: active CISA records active exploitation. Automatable: yes, technical impact: total.
  • Indexed PoC 1 indexed Published artifacts you can open, in Nuclei.
  • EPSS 90% chance in 30 days A model prediction, not an observation. Higher than 100% of all scored CVEs.
IndexArtifactStarsFirst seen
Nuclei Apache Tomcat - Remote Code Execution via JMX Ports

Waratek Defense Posture

Protected by RASP

A Waratek agent blocks this today.

Applicable rule: A researcher classified this CVE as MITIGATED-BY-SECURE-RULE, protected by the ARMR Deserial RCE rule.

  • Protection full a general security rule for the vulnerability class
  • Action available security rule
  • Review human manual-review
  • Record active
Decided by manual-classification : A researcher's recorded decision for this specific CVE
Finding A researcher classified this CVE as MITIGATED-BY-SECURE-RULE, protected by the ARMR Deserial RCE rule.

Waratek research note

written 2026-09-14

Written by a Waratek engineer reviewing this CVE. A written classification sets the status directly, ahead of every automated scope rule except a withdrawal.

Comments

Rule Name: Deserial RCE rule

The ARMR Deserial RCE rule blocks the RCE: attackers exploit JmxRemoteLifecycleListener by sending a serialized gadget payload in place of JMX credentials, triggering ObjectInputStream.readObject() during RMI authentication.

CVSS

9.8 CRITICAL v3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H NVD Primary published
CVSS 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CISA-ADP Secondary
CVSS 2.0 7.5 no band published AV:N/AC:L/Au:N/C:P/I:P/A:P NVD Primary

Affected Software & Releases

🏛️ Oracle CPU Advisories & Products

AdvisoryTypeQuarterProducts Oracle named in risk matrix
Oracle Critical Patch Update October 2017 CPU 2017-Q4 Oracle Database Server / WLM (Apache Tomcat) (12.2.0.1)

Indexed Oracle Components & Versions

FamilyComponentOracle's version cell (verbatim)Indexed as
Oracle Database Server WLM (Apache Tomcat) 12.2.0.1 12.2.0.1

☕ Maven Library Packages

Artifact coordinates and fix boundaries from OSV.dev
Package CoordinateIntroducedFixedLast affected
org.apache.tomcat:tomcat-catalina-jmx-remote 0 6.0.48 unbounded
org.apache.tomcat:tomcat-catalina-jmx-remote 7.0.0 7.0.73 unbounded
org.apache.tomcat:tomcat-catalina-jmx-remote 8.0.0 8.0.39 unbounded
org.apache.tomcat:tomcat-catalina-jmx-remote 8.5.0 8.5.7 unbounded
org.apache.tomcat:tomcat-catalina-jmx-remote 9.0.0.M1 9.0.0.M12 unbounded
org.apache.tomcat:tomcat-catalina 0 6.0.48 unbounded
org.apache.tomcat:tomcat-catalina 7.0.0 7.0.73 unbounded
org.apache.tomcat:tomcat-catalina 8.0.0 8.0.39 unbounded
org.apache.tomcat:tomcat-catalina 8.5.0 8.5.7 unbounded
org.apache.tomcat:tomcat-catalina 9.0.0.M1 9.0.0.M12 unbounded

🖥️ Product CPEs & Version Ranges

21 product(s) over 66 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd apache tomcat generic < 6.0.48 · ≥ 7.0.0 and < 7.0.73 · ≥ 8.0 and < 8.0.39 · ≥ 8.5.0 and < 8.5.7 · 9.0.0 · 9.0.0:milestone1 · 9.0.0:milestone10 · 9.0.0:milestone11 · 9.0.0:milestone2 · 9.0.0:milestone3 · 9.0.0:milestone4 · 9.0.0:milestone5 · 9.0.0:milestone6 · 9.0.0:milestone7 · 9.0.0:milestone8 · 9.0.0:milestone9
nvd canonical ubuntu linux generic 16.04
nvd debian debian linux generic 8.0
nvd netapp 7-mode transition tool generic any version
nvd netapp oncommand insight generic any version
nvd netapp oncommand shift generic any version
nvd netapp snap creator framework generic any version
nvd oracle agile engineering data management generic 6.1.3 · 6.2.0 · 6.2.1.0
nvd oracle agile product lifecycle management generic 9.3.5 · 9.3.6
nvd oracle communications application session controller generic 3.7.1 · 3.8.0
nvd oracle communications instant messaging server generic 10.0.1
nvd oracle communications interactive session recorder generic 6.0 · 6.1 · 6.2
nvd oracle hospitality guest access generic 4.2.0 · 4.2.1
nvd oracle micros relate crm software generic 10.8 · 11.4
nvd oracle micros retail xbri loss prevention generic 10.0.1 · 10.5.0 · 10.6.0 · 10.7.7 · 10.8.0 · 10.8.1
nvd oracle mysql enterprise monitor generic ≤ 3.2.8.2223 · ≥ 3.3.0 and ≤ 3.3.4.3247 · ≥ 3.4.0 and ≤ 3.4.2.4181
nvd oracle retail convenience and fuel pos software generic 2.1.132
nvd oracle transportation management generic 6.3.0 · 6.3.1 · 6.3.2 · 6.3.3 · 6.3.4 · 6.3.5 · 6.3.6 · 6.3.7
osv org.apache.tomcat tomcat-catalina generic < 6.0.48 · ≥ 7.0.0 and < 7.0.73 · ≥ 8.0.0 and < 8.0.39 · ≥ 8.5.0 and < 8.5.7 · ≥ 9.0.0 and < 9.0.0
osv org.apache.tomcat tomcat-catalina-jmx-remote generic < 6.0.48 · ≥ 7.0.0 and < 7.0.73 · ≥ 8.0.0 and < 8.0.39 · ≥ 8.5.0 and < 8.5.7 · ≥ 9.0.0 and < 9.0.0
nvd redhat jboss enterprise web server generic 3.0.0

References

URLTags
https://github.com/apache/tomcat/commit/0e83ad3e547fc9a75a258799ef581249b40a82a6 WEB
https://github.com/apache/tomcat/commit/292d6ccdc9edbf80859929b0af070b2ea99fa688 WEB
https://github.com/apache/tomcat/commit/7e3a037055cca4a17e90b49399fb1bab4dd7c821 WEB
https://github.com/apache/tomcat80/commit/0f76016a4ec45635e450ada9c84ff7ee0c5f3799 WEB
https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E WEB
https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc@%3Cdev.tomcat.apache.org%3E WEB
https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E WEB
https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95@%3Cdev.tomcat.apache.org%3E WEB
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E WEB
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb@%3Cdev.tomcat.apache.org%3E WEB

Timeline

Published 2017-04-06 Last modified 2026-08-25
Published2017-04-06By the CVE Program.
NVD record modified2026-08-25NVD's own last-modified date for this record.
Classification created2026-09-14First commit adding this CVE's research note.
Last VRT activity2026-09-14Most recent commit touching this CVE's classification, patch or rule file.