CVE-2016-8735: Apache Tomcat Remote Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-05-12. EPSS: 90.3% chance of exploitation in the next 30 days.

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

Affected products

  • Apache Tomcat: before 6.0.48 (fixed in 6.0.48); from 7.0.0, before 7.0.73 (fixed in 7.0.73); from 8.0, before 8.0.39 (fixed in 8.0.39); from 8.5.0, before 8.5.7 (fixed in 8.5.7); version 9.0.0 only
  • Canonical Ubuntu Linux: version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • Netapp 7-Mode Transition Tool: affected versions not specified
  • Netapp Oncommand Insight: affected versions not specified
  • Netapp Oncommand Shift: affected versions not specified
  • Netapp Snap Creator Framework: affected versions not specified
  • Oracle Agile Engineering Data Management: version 6.1.3 only; version 6.2.0 only; version 6.2.1.0 only
  • Oracle Agile Product Lifecycle Management: version 9.3.5 only; version 9.3.6 only
  • Oracle Communications Application Session Controller: version 3.7.1 only; version 3.8.0 only
  • Oracle Communications Instant Messaging Server: version 10.0.1 only
  • Oracle Communications Interactive Session Recorder: version 6.0 only; version 6.1 only; version 6.2 only
  • Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
  • Oracle Micros Relate CRM Software: version 10.8 only; version 11.4 only
  • Oracle Micros Retail Xbri Loss Prevention: version 10.0.1 only; version 10.5.0 only; version 10.6.0 only; version 10.7.7 only; version 10.8.0 only; version 10.8.1 only
  • Oracle MySQL Enterprise Monitor: up to and including 3.2.8.2223; from 3.3.0, up to and including 3.3.4.3247; from 3.4.0, up to and including 3.4.2.4181
  • Oracle Retail Convenience And Fuel Pos Software: version 2.1.132 only
  • Oracle Transportation Management: version 6.3.0 only; version 6.3.1 only; version 6.3.2 only; version 6.3.3 only; version 6.3.4 only; version 6.3.5 only; …
  • Red Hat JBoss Enterprise Web Server: version 3.0.0 only

Published 2017-04-06. Last modified 2026-08-25.