suse · CVE-2016-8735

Quick triage

Priority: medium Published: 2021-05-30 13:47:07 UTC Updated: 2025-11-05 04:17:30 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-8735 severity moderate: SUSE including 62 source package names (tomcat-7.0.78-7.13.4, tomcat-8.0.32-10.13.2, …), 156 product×package rows across 18 product lines (SUSE Linux Enterprise High Performance Computing 12 SP5, SUSE Linux Enterprise Point of Sale 11 SP3, … (18 product lines)): Fixed 156.

Description:

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

cvelogic Threat Intelligence