Junglewise Threat Intelligence

CVE-2016-8735: Apache Tomcat Improper Access Control vulnerability

CVE-2016-8735 · Severity: critical · CVSS 3 · Exploited in the wild · Published 2022-05-13

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat is vulnerable to remote code execution when the JmxRemoteLifecycleListener is enabled and an attacker can access the JMX ports. The vulnerability arises because the listener lacked security updates consistent with CVE-2016-3427 regarding credential type validation.

Affected products

  • Apache Tomcat before 6.0.48
  • Apache Tomcat 7.x before 7.0.73
  • Apache Tomcat 8.x before 8.0.39
  • Apache Tomcat 8.5.x before 8.5.7
  • Apache Tomcat 9.x before 9.0.0.M12

Timeline

  • 2023-05-12: disclosed
  • exploited: Reported as exploited in the wild and listed in CISA KEV catalog.

Related threats