Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
History
No history.
Information
Published : 2017-04-06 21:59
Updated : 2024-06-27 19:23
NVD link : CVE-2016-8735
Mitre link : CVE-2016-8735
CVE.ORG link : CVE-2016-8735
JSON object : View
Products Affected
redhat
- jboss_enterprise_web_server
oracle
- micros_relate_crm_software
- retail_convenience_and_fuel_pos_software
- agile_plm
- micros_retail_xbri_loss_prevention
- agile_engineering_data_management
- communications_application_session_controller
- communications_interactive_session_recorder
- mysql_enterprise_monitor
- hospitality_guest_access
- communications_instant_messaging_server
- transportation_management
netapp
- oncommand_insight
- oncommand_shift
- snap_creator_framework
- 7-mode_transition_tool
canonical
- ubuntu_linux
apache
- tomcat
debian
- debian_linux
CWE