CVE-2016-8735Critical· 9.8▾ Hadal⚠ Exploited in the wildRemote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue e…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 18.1 · exploitation 25
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Jun 2, 2023
Last analysed / modified upstream
90%
Added to the CISA catalog on May 12, 2023. Federal remediation due Jun 2, 2023. View catalog ↗
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
tomcat < 6.0.48tomcat >= 7.0.0, < 7.0.73tomcat >= 8.0, < 8.0.39tomcat >= 8.5.0, < 8.5.7tomcat = 9.0.0ubuntu_linux = 16.047-mode_transition_tooloncommand_insightoncommand_shiftsnap_creator_frameworkdebian_linux = 8.0jboss_enterprise_web_server = 3.0.0agile_engineering_data_management = 6.1.3agile_engineering_data_management = 6.2.0agile_engineering_data_management = 6.2.1.0agile_product_lifecycle_management = 9.3.5agile_product_lifecycle_management = 9.3.6communications_application_session_controller = 3.7.1communications_application_session_controller = 3.8.0communications_instant_messaging_server = 10.0.1communications_interactive_session_recorder = 6.0communications_interactive_session_recorder = 6.1communications_interactive_session_recorder = 6.2hospitality_guest_access = 4.2.0hospitality_guest_access = 4.2.1micros_relate_crm_software = 10.8micros_relate_crm_software = 11.4micros_retail_xbri_loss_prevention = 10.0.1micros_retail_xbri_loss_prevention = 10.5.0micros_retail_xbri_loss_prevention = 10.6.0micros_retail_xbri_loss_prevention = 10.7.7micros_retail_xbri_loss_prevention = 10.8.0micros_retail_xbri_loss_prevention = 10.8.1mysql_enterprise_monitor <= 3.2.8.2223mysql_enterprise_monitor >= 3.3.0, <= 3.3.4.3247mysql_enterprise_monitor >= 3.4.0, <= 3.4.2.4181retail_convenience_and_fuel_pos_software = 2.1.132transportation_management = 6.3.0transportation_management = 6.3.1transportation_management = 6.3.2transportation_management = 6.3.3transportation_management = 6.3.4transportation_management = 6.3.5transportation_management = 6.3.6transportation_management = 6.3.7Upgrade past the affected range:
tomcat 8.5.7Connected by shared product, vendor, weakness, or advisory.
CVE-2017-12617High· 8.1When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g
CVE-2017-12615High· 8.1When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g
CVE-2026-34486High· 7.5Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …
CVE-2026-68569High· 8.1Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g
CVE-2022-25762High· 8.6If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use…
CVE-2021-33037Medium· 5.3Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse pr…