Vulnerability record · CVE-2016-8735 · published 6 April 2017
CVE-2016-8735: Apache Tomcat JmxRemoteLifecycleListener remote code execution
Apache · Tomcat
Apache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness that allows remote code execution. It affects Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 when that listener is enabled and JMX ports are reachable. Because it is network-reachable with no authentication or user interaction, it is a serious exposure for any host exposing JMX.
Description
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, KEV listing with a past due date, and EPSS near 0.90 make this an actively exploited, unauthenticated RCE.
What it is
Apache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness that allows remote code execution. It affects Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 when that listener is enabled and JMX ports are reachable. Because it is network-reachable with no authentication or user interaction, it is a serious exposure for any host exposing JMX.
Impact
An unauthenticated remote attacker can execute arbitrary code with the privileges of the Tomcat process, leading to full host compromise.
Attack surface
Reached over the network via exposed JMX ports on Tomcat instances that use JmxRemoteLifecycleListener; the CVSS vector shows no privileges or user interaction required.
Exploitation
CVE-2016-8735 is listed in CISA KEV with a 2023-06-02 remediation due date, and EPSS gives a 30-day probability of about 0.90 (99.8th percentile), indicating active exploitation and high likelihood. No ransomware campaign use is documented.
What to do
- Upgrade Tomcat to a fixed release: 6.0.48, 7.0.73, 8.0.39, 8.5.7, or 9.0.0.M12 and later, per vendor advisories.
- If JmxRemoteLifecycleListener is not required, remove it from server configuration.
- Restrict JMX/RMI ports with firewall rules and bind to management interfaces only, never the public internet.
- Apply the referenced Oracle, Red Hat, Debian and other vendor patches for bundled Tomcat components.
- Verify the credential-type fix is present, since the flaw stems from missing the CVE-2016-3427 consistency update.
Detection
- Monitor network traffic to JMX/RMI ports for unexpected external connections or serialized payloads.
- Audit Tomcat server.xml for JmxRemoteLifecycleListener usage and flag exposed JMX ports.
- Alert on suspicious child processes or command execution spawned by the Tomcat JVM.
- Track Tomcat versions in inventory against the fixed release list and flag unpatched instances.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-8735 to the Known Exploited Vulnerabilities catalog on 12 May 2023 as "Apache Tomcat Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 2 June 2023.
Affected products
19 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-8735 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-8735), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.