CVE-2016-8735

Apache Tomcat: Remote Code Execution

As of , CVE-2016-8735 in Apache Tomcat is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 12 May 2023
US federal deadline
2 June 202321 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.90Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.04 on 12 May 2023EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: tomcat.apache.orgLinks below, from CISA's entry.

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.

CISA's description

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

The CVE record's description, from apache

CVE published
6 April 2017
Assigned by
apache
CVSS
9.8 Critical (CVSS 3.1, from CISA-ADP)
CWE-284
Improper Access Control
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Tomcat: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2017-12617Remote Code ExecutionApache TomcatPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2020-1938Improper Privilege ManagementApache TomcatPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2025-24813Path EquivalenceApache TomcatPatch this weekMetasploit module; EPSS 0.990.99
CVE-2017-12615on Windows Remote Code ExecutionApache TomcatPatch this weekRansomware use; EPSS 0.990.99
CVE-2026-34486Missing Encryption of Sensitive DataApache TomcatPatch soon0.07

Read further