← לוח פגיעויות

CVE-2016-8735

קריטית 9.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Apache Tomcat Remote Code Execution Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
90% (אחוזון 100) נכון ל-25/7/2026

מוצרים מושפעים

apache: tomcat; canonical: ubuntu linux; netapp: 7-mode transition tool; netapp: oncommand insight; netapp: oncommand shift; netapp: snap creator framework; debian: debian linux; redhat: jboss enterprise web server; oracle: agile engineering data management; oracle: agile plm; oracle: communications application session controller; oracle: communications instant messaging server; oracle: communications interactive session recorder; oracle: hospitality guest access; oracle: micros relate crm software

קישורים