PT-2016-3139 · Apache+3 · Apache Tomcat+3

Pierre Ernst

·

Publicado

2016-11-08

·

Atualizado

2025-08-31

·

CVE-2016-8735

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 6.0.0 through 6.0.47 Apache Tomcat versions 7.0.0 through 7.0.72 Apache Tomcat versions 8.0.0 through 8.0.38 Apache Tomcat versions 8.5.0 through 8.5.6 Apache Tomcat versions 9.0.0.M1 through 9.0.0.M11
Description The issue allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. This is due to the listener not being updated for consistency with an Oracle patch that affected credential types. The estimated number of potentially affected devices is not specified. There is no information about real-world incidents where this issue was exploited. The JmxRemoteLifecycleListener was not updated to account for the fix, leaving Tomcat installations using this listener vulnerable to remote code execution. API Endpoints are not specified, but the issue involves access to JMX ports. Vulnerable parameters or variables are not explicitly mentioned, but the issue is related to credential types.
Recommendations For Apache Tomcat versions 6.0.0 through 6.0.47, update to version 6.0.48 or later. For Apache Tomcat versions 7.0.0 through 7.0.72, update to version 7.0.73 or later. For Apache Tomcat versions 8.0.0 through 8.0.38, update to version 8.0.39 or later. For Apache Tomcat versions 8.5.0 through 8.5.6, update to version 8.5.7 or later. For Apache Tomcat versions 9.0.0.M1 through 9.0.0.M11, update to version 9.0.0.M12 or later. As a temporary workaround, consider disabling the JmxRemoteLifecycleListener until a patch is available. Restrict access to JMX ports to minimize the risk of exploitation.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2558
BDU:2017-01545
CVE-2016-8735
DLA-728-1
DLA-729-1
DSA-3738-1
DSA-3739-1
GHSA-CW54-59PW-4G8C
MGASA-2016-0417
OPENSUSE-SU-2016_3129-1
OPENSUSE-SU-2016_3144-1
RHSA-2017:0455
RHSA-2017:0456
SUSE-SU-2016:3079-1
SUSE-SU-2016:3081-1
SUSE-SU-2017:1632-1
SUSE-SU-2017:1660-1
USN-3177-1
USN-3177-2
USN-4557-1
USN-7242-1

Produtos afetados

Alt Linux
Apache Tomcat
Suse
Ubuntu