CVE-2016-8735
Apache Tomcat: Remote Code Execution
As of , CVE-2016-8735 in Apache Tomcat is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 12 May 2023
- US federal deadline
- 2 June 202321 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.90Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.04 on 12 May 2023EPSS on the day CISA listed it.
- Public exploit
- None foundNeither Metasploit nor Exploit-DB lists one.
- Fix
- Vendor advice: tomcat.apache.orgLinks below, from CISA's entry.
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.
CISA's description
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
The CVE record's description, from apache
- CVE published
- 6 April 2017
- Assigned by
- apache
- CVSS
- 9.8 Critical (CVSS 3.1, from CISA-ADP)
- CWE-284
- Improper Access Control
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Tomcat: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2017-12617Remote Code Execution | Apache Tomcat | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2020-1938Improper Privilege Management | Apache Tomcat | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2025-24813Path Equivalence | Apache Tomcat | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2017-12615on Windows Remote Code Execution | Apache Tomcat | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| CVE-2026-34486Missing Encryption of Sensitive Data | Apache Tomcat | Patch soon | 0.07 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org