View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2016-8735 severity moderate: SUSE including 62 source package names (tomcat-7.0.78-7.13.4, tomcat-8.0.32-10.13.2, …), 156 product×package rows across 18 product lines (SUSE Linux Enterprise High Performance Computing 12 SP5, SUSE Linux Enterprise Point of Sale 11 SP3, … (18 product lines)): Fixed 156.
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.