---
id: CVE-2016-8735
title: >-
  Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before
  7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if
  JmxRemoteLifecycleListener is used and an attacker can reach JMX ports
summary: >-
  Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before
  7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if
  JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The
  issue e…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: apache
product: tomcat
affected:
  - tomcat < 6.0.48
  - 'tomcat >= 7.0.0, < 7.0.73'
  - 'tomcat >= 8.0, < 8.0.39'
  - 'tomcat >= 8.5.0, < 8.5.7'
  - tomcat = 9.0.0
  - ubuntu_linux = 16.04
  - 7-mode_transition_tool
  - oncommand_insight
  - oncommand_shift
  - snap_creator_framework
  - debian_linux = 8.0
  - jboss_enterprise_web_server = 3.0.0
  - agile_engineering_data_management = 6.1.3
  - agile_engineering_data_management = 6.2.0
  - agile_engineering_data_management = 6.2.1.0
  - agile_product_lifecycle_management = 9.3.5
  - agile_product_lifecycle_management = 9.3.6
  - communications_application_session_controller = 3.7.1
  - communications_application_session_controller = 3.8.0
  - communications_instant_messaging_server = 10.0.1
  - communications_interactive_session_recorder = 6.0
  - communications_interactive_session_recorder = 6.1
  - communications_interactive_session_recorder = 6.2
  - hospitality_guest_access = 4.2.0
  - hospitality_guest_access = 4.2.1
  - micros_relate_crm_software = 10.8
  - micros_relate_crm_software = 11.4
  - micros_retail_xbri_loss_prevention = 10.0.1
  - micros_retail_xbri_loss_prevention = 10.5.0
  - micros_retail_xbri_loss_prevention = 10.6.0
  - micros_retail_xbri_loss_prevention = 10.7.7
  - micros_retail_xbri_loss_prevention = 10.8.0
  - micros_retail_xbri_loss_prevention = 10.8.1
  - mysql_enterprise_monitor <= 3.2.8.2223
  - 'mysql_enterprise_monitor >= 3.3.0, <= 3.3.4.3247'
  - 'mysql_enterprise_monitor >= 3.4.0, <= 3.4.2.4181'
  - retail_convenience_and_fuel_pos_software = 2.1.132
  - transportation_management = 6.3.0
  - transportation_management = 6.3.1
  - transportation_management = 6.3.2
  - transportation_management = 6.3.3
  - transportation_management = 6.3.4
  - transportation_management = 6.3.5
  - transportation_management = 6.3.6
  - transportation_management = 6.3.7
patched:
  - tomcat 8.5.7
published: '2017-04-06'
updated: '2026-08-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2016-8735'
references:
  - url: 'http://rhn.redhat.com/errata/RHSA-2017-0457.html'
    label: security@apache.org
  - url: 'http://seclists.org/oss-sec/2016/q4/502'
    label: security@apache.org
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1767644'
    label: security@apache.org
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1767656'
    label: security@apache.org
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1767676'
    label: security@apache.org
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1767684'
    label: security@apache.org
  - url: 'http://tomcat.apache.org/security-6.html'
    label: security@apache.org
  - url: 'http://tomcat.apache.org/security-7.html'
    label: security@apache.org
  - url: 'http://tomcat.apache.org/security-8.html'
    label: security@apache.org
  - url: 'http://tomcat.apache.org/security-9.html'
    label: security@apache.org
  - url: 'http://www.debian.org/security/2016/dsa-3738'
    label: security@apache.org
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
    label: security@apache.org
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
    label: security@apache.org
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
    label: security@apache.org
  - url: 'http://www.securityfocus.com/bid/94463'
    label: security@apache.org
  - url: 'http://www.securitytracker.com/id/1037331'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:0455'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:0456'
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: 'https://security.netapp.com/advisory/ntap-20180607-0001/'
    label: security@apache.org
  - url: 'https://usn.ubuntu.com/4557-1/'
    label: security@apache.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
    label: security@apache.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
    label: security@apache.org
  - url: 'http://rhn.redhat.com/errata/RHSA-2017-0457.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/oss-sec/2016/q4/502'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1767644'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1767656'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1767676'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://svn.apache.org/viewvc?view=revision&revision=1767684'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-6.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-7.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-8.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-9.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.debian.org/security/2016/dsa-3738'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/94463'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1037331'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:0455'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:0456'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20180607-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4557-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-8735
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
epss: 0.90338
epssPercentile: 0.99796
kev: true
kevDateAdded: '2023-05-12'
kevDueDate: '2023-06-02'
kevRansomware: false
exploited: true
ingestedAt: '2026-08-25T17:29:28.964Z'
---

## Overview

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

## Affected

- `tomcat < 6.0.48`
- `tomcat >= 7.0.0, < 7.0.73`
- `tomcat >= 8.0, < 8.0.39`
- `tomcat >= 8.5.0, < 8.5.7`
- `tomcat = 9.0.0`
- `ubuntu_linux = 16.04`
- `7-mode_transition_tool`
- `oncommand_insight`
- `oncommand_shift`
- `snap_creator_framework`
- `debian_linux = 8.0`
- `jboss_enterprise_web_server = 3.0.0`
- `agile_engineering_data_management = 6.1.3`
- `agile_engineering_data_management = 6.2.0`
- `agile_engineering_data_management = 6.2.1.0`
- `agile_product_lifecycle_management = 9.3.5`
- `agile_product_lifecycle_management = 9.3.6`
- `communications_application_session_controller = 3.7.1`
- `communications_application_session_controller = 3.8.0`
- `communications_instant_messaging_server = 10.0.1`
- `communications_interactive_session_recorder = 6.0`
- `communications_interactive_session_recorder = 6.1`
- `communications_interactive_session_recorder = 6.2`
- `hospitality_guest_access = 4.2.0`
- `hospitality_guest_access = 4.2.1`
- `micros_relate_crm_software = 10.8`
- `micros_relate_crm_software = 11.4`
- `micros_retail_xbri_loss_prevention = 10.0.1`
- `micros_retail_xbri_loss_prevention = 10.5.0`
- `micros_retail_xbri_loss_prevention = 10.6.0`
- `micros_retail_xbri_loss_prevention = 10.7.7`
- `micros_retail_xbri_loss_prevention = 10.8.0`
- `micros_retail_xbri_loss_prevention = 10.8.1`
- `mysql_enterprise_monitor <= 3.2.8.2223`
- `mysql_enterprise_monitor >= 3.3.0, <= 3.3.4.3247`
- `mysql_enterprise_monitor >= 3.4.0, <= 3.4.2.4181`
- `retail_convenience_and_fuel_pos_software = 2.1.132`
- `transportation_management = 6.3.0`
- `transportation_management = 6.3.1`
- `transportation_management = 6.3.2`
- `transportation_management = 6.3.3`
- `transportation_management = 6.3.4`
- `transportation_management = 6.3.5`
- `transportation_management = 6.3.6`
- `transportation_management = 6.3.7`

## Remediation

Upgrade past the affected range:

- `tomcat 8.5.7`
