CVE-2016-8735
Executive Summary
Apache Tomcat versions prior to 6.0.48, 7.0.73, 8.0.39, 8.5.7, and 9.0.0.M12 are vulnerable to remote code execution when the JmxRemoteLifecycleListener is enabled and an attacker can access JMX ports. The flaw stems from an outdated listener implementation that failed to incorporate the Oracle CVE-2016-3427 patch, allowing attackers to execute arbitrary code. The vulnerability is actively exploited in the wild, as identified by CISA’s KEV list.
Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2017-04-06T21:59:00.243 - Last Modified: 2026-08-25T16:28:27.310
[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2023-05-12)
Original Description: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
"Work out your own salvation. Do not depend on others."
— Buddha