Executive brief
Apache Tomcat is vulnerable to remote code execution when the JmxRemoteLifecycleListener is enabled and an attacker can access the JMX ports. The vulnerability arises because the listener lacked security updates consistent with CVE-2016-3427 regarding credential type validation.
Affected products
- Apache Tomcat before 6.0.48
- Apache Tomcat 7.x before 7.0.73
- Apache Tomcat 8.x before 8.0.39
- Apache Tomcat 8.5.x before 8.5.7
- Apache Tomcat 9.x before 9.0.0.M12
Timeline
- 2023-05-12: disclosed
- exploited: Reported as exploited in the wild and listed in CISA KEV catalog.