[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2016-8735 -- tomcat6

ID: oval:org.secpod.oval:def:1900516Date: (C)2019-02-27   (M)2023-12-20
Class: VULNERABILITYFamily: unix




Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reachJMX ports. The issue exists because this listener wasn"t updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

Platform:
Ubuntu 16.04
Ubuntu 14.04
Product:
tomcat6
Reference:
CVE-2016-8735
CVE    1
CVE-2016-8735
CPE    174
cpe:/a:apache:tomcat:7.0.71
cpe:/a:apache:tomcat:7.0.70
cpe:/a:apache:tomcat:7.0.62
cpe:/a:apache:tomcat:7.0.61
...

© SecPod Technologies