CVE-2016-8735: Apache Tomcat
EPSS90.3%No. 459 of 1739 in KEV
CVE year2016~7 yrs before listing
Same vendor in KEV41
Same product6
| Field | Value |
|---|---|
| Vendor | Apache |
| Product | Tomcat |
| Name | Apache Tomcat Remote Code Execution Vulnerability |
| Added to KEV | 2023-05-12 |
| US federal due date | 2023-06-02 |
| Ransomware use | Unknown |
| CWE | CWE-284 |
CISA description
Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2026-34486 | Apache Tomcat | 2026-08-04 | 6.5% | Unknown |
| CVE-2025-24813 | Apache Tomcat | 2025-04-01 | 99.9% | Unknown |
| CVE-2017-12617 | Apache Tomcat | 2022-03-25 | 99.9% | Unknown |
| CVE-2017-12615 | Apache Tomcat | 2022-03-25 | 99.6% | Known |
| CVE-2020-1938 | Apache Tomcat | 2022-03-03 | 99.2% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Apache Tomcat vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-05-12.