{"id":"CVE-2016-8735","description":"Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.","cvssScore":9.8,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssMetrics":[{"version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","sourceName":"CISA-ADP","type":"Secondary"},{"version":"2.0","score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-284"],"resolved":"MITIGATED-BY-RASP","published":"2017-04-06","lastModified":"2026-08-25","affectedProducts":[{"vendor":"apache","product":"tomcat","versionEnd":"\u003c6.0.48"},{"vendor":"apache","product":"tomcat","versionStart":"\u003e=7.0.0","versionEnd":"\u003c7.0.73"},{"vendor":"apache","product":"tomcat","versionStart":"\u003e=8.0","versionEnd":"\u003c8.0.39"},{"vendor":"apache","product":"tomcat","versionStart":"\u003e=8.5.0","versionEnd":"\u003c8.5.7"},{"vendor":"apache","product":"tomcat","version":"9.0.0"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone1"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone10"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone11"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone2"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone3"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone4"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone5"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone6"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone7"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone8"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone9"},{"vendor":"canonical","product":"ubuntu linux","version":"16.04"},{"vendor":"netapp","product":"7-mode transition tool"},{"vendor":"netapp","product":"oncommand insight"},{"vendor":"netapp","product":"oncommand shift"}],"totalAffectedProducts":19,"references":[{"url":"https://github.com/apache/tomcat/commit/0e83ad3e547fc9a75a258799ef581249b40a82a6","source":"osv","tags":["WEB"]},{"url":"https://github.com/apache/tomcat/commit/292d6ccdc9edbf80859929b0af070b2ea99fa688","source":"osv","tags":["WEB"]},{"url":"https://github.com/apache/tomcat/commit/7e3a037055cca4a17e90b49399fb1bab4dd7c821","source":"osv","tags":["WEB"]},{"url":"https://github.com/apache/tomcat80/commit/0f76016a4ec45635e450ada9c84ff7ee0c5f3799","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc@%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95@%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb@%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]}],"reasoning":{"decidingSource":"manual-classification","decidingReason":"A researcher classified this CVE as MITIGATED-BY-SECURE-RULE, protected by the ARMR Deserial RCE rule.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"matched","status":"MITIGATED-BY-RASP","detail":"A researcher classified this CVE as MITIGATED-BY-SECURE-RULE, protected by the ARMR Deserial RCE rule.","decisive":true}],"affectedPackages":[{"name":"org.apache.tomcat:tomcat-catalina-jmx-remote","introduced":"0","fixed":"6.0.48"},{"name":"org.apache.tomcat:tomcat-catalina-jmx-remote","introduced":"7.0.0","fixed":"7.0.73"},{"name":"org.apache.tomcat:tomcat-catalina-jmx-remote","introduced":"8.0.0","fixed":"8.0.39"},{"name":"org.apache.tomcat:tomcat-catalina-jmx-remote","introduced":"8.5.0","fixed":"8.5.7"},{"name":"org.apache.tomcat:tomcat-catalina-jmx-remote","introduced":"9.0.0.M1","fixed":"9.0.0.M12"},{"name":"org.apache.tomcat:tomcat-catalina","introduced":"0","fixed":"6.0.48"},{"name":"org.apache.tomcat:tomcat-catalina","introduced":"7.0.0","fixed":"7.0.73"},{"name":"org.apache.tomcat:tomcat-catalina","introduced":"8.0.0","fixed":"8.0.39"},{"name":"org.apache.tomcat:tomcat-catalina","introduced":"8.5.0","fixed":"8.5.7"},{"name":"org.apache.tomcat:tomcat-catalina","introduced":"9.0.0.M1","fixed":"9.0.0.M12"}]},"relatedFiles":{"classificationFile":"data/classifications/CVE-2016-8735.md","classificationContent":"LS0tCmN2ZUlkOiBDVkUtMjAxNi04NzM1CnJlc29sdXRpb246IE1JVElHQVRFRC1CWS1TRUNVUkUtUlVMRQotLS0KCiMjIENvbW1lbnRzCgoqKlJ1bGUgTmFtZSoqOiBEZXNlcmlhbCBSQ0UgcnVsZQoKVGhlIEFSTVIgRGVzZXJpYWwgUkNFIHJ1bGUgYmxvY2tzIHRoZSBSQ0U6IGF0dGFja2VycyBleHBsb2l0IGBKbXhSZW1vdGVMaWZlY3ljbGVMaXN0ZW5lcmAgYnkgc2VuZGluZyBhIHNlcmlhbGl6ZWQgZ2FkZ2V0IHBheWxvYWQgaW4gcGxhY2Ugb2YgSk1YIGNyZWRlbnRpYWxzLCB0cmlnZ2VyaW5nIGBPYmplY3RJbnB1dFN0cmVhbS5yZWFkT2JqZWN0KClgIGR1cmluZyBSTUkgYXV0aGVudGljYXRpb24uCg==","classificationCreated":"2026-09-14T16:51:25+01:00"},"oracleAdvisories":[{"advisory":"Oracle Critical Patch Update October 2017","releaseType":"CPU","quarter":"2017-Q4","url":"https://www.oracle.com/security-alerts/cpuoct2017.html","products":[{"product":"Oracle Database Server","component":"WLM (Apache Tomcat)","affectedVersions":"12.2.0.1"}]}],"assessment":{"record":{"state":"active"},"protection":{"level":"full","mechanisms":["security-rule"]},"action":{"state":"available","type":"security-rule"},"review":{"state":"human","basis":"manual-review"}},"exploits":[{"source":"nuclei","url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/code/cves/2016/CVE-2016-8735.yaml","title":"Apache Tomcat - Remote Code Execution via JMX Ports"}],"signals":{"hasPOC":true,"pocCount":1,"pocSources":["nuclei"]},"kev":{"inKEV":true,"dateAdded":"2023-05-12","dueDate":"2023-06-02","knownRansomwareUse":"Unknown"},"epss":{"available":true,"score":0.90338,"percentile":0.99791},"ssvc":{"available":true,"exploitation":"active","automatable":"yes","technicalImpact":"total"},"lastActivity":"2026-09-14T16:51:25+01:00"}