← Back to browse · API

CVE-2016-8735

Severity
CRITICAL
CVSS
9.8
EPSS
0.90338
Risk score
56.62
CISA KEV
Yes
PoC
No
Published
2017-04-06
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-3642, GHSA-CW54-59PW-4G8C
Products
Apache Software Foundation:Apache Tomcat 7.x before 7.0.73, Apache Software Foundation:Apache Tomcat 8.5.x before 8.5.7, Apache Software Foundation:Apache Tomcat 8.x before 8.0.39, Apache Software Foundation:Apache Tomcat 9.x before 9.0.0.M12, Apache Software Foundation:Apache Tomcat before 6.0.48, Apache:Tomcat
Sources
cisa.gov CVE-2016-8735
euvd EUVD-2022-3642

Description

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

References