CVE-2016-8735
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apache Tomcat Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 90% (אחוזון 100) נכון ל-25/7/2026
מוצרים מושפעים
apache: tomcat; canonical: ubuntu linux; netapp: 7-mode transition tool; netapp: oncommand insight; netapp: oncommand shift; netapp: snap creator framework; debian: debian linux; redhat: jboss enterprise web server; oracle: agile engineering data management; oracle: agile plm; oracle: communications application session controller; oracle: communications instant messaging server; oracle: communications interactive session recorder; oracle: hospitality guest access; oracle: micros relate crm software
קישורים
- http://tomcat.apache.org/security-6.html Release NotesVendor Advisory
- http://tomcat.apache.org/security-7.html Release NotesVendor Advisory
- http://tomcat.apache.org/security-8.html Release NotesVendor Advisory
- http://tomcat.apache.org/security-9.html Release NotesVendor Advisory
- http://tomcat.apache.org/security-6.html Release NotesVendor Advisory
- http://tomcat.apache.org/security-7.html Release NotesVendor Advisory
- http://tomcat.apache.org/security-8.html Release NotesVendor Advisory
- http://tomcat.apache.org/security-9.html Release NotesVendor Advisory
- http://svn.apache.org/viewvc?view=revision&revision=1767644 Broken LinkPatch
- http://svn.apache.org/viewvc?view=revision&revision=1767656 Broken LinkPatch