CVE Listesine Dön
CVE-2016-8735 CISA KEV · Aktif Sömürülüyor

Vulnerability in Apache Tomcat

CVSS Skor

9.8

EPSS İhtimal

%90.3

Risk Skoru

17.7

Yayın

9 yıl önce

Yama yalnızca bazı ürün veya sürümlerde mevcut

Kanıt listesindeki ürün ve sürüm eşleşmesini kontrol edin; bazı varyantlar hâlâ etkileniyor olabilir.

Envanterimdeki Etkisi

Yalnızca hesabınıza eklediğiniz kişisel ürünler değerlendirilir; kurumsal envanter burada görünmez.

Oturum kontrol ediliyor…

Zafiyet Açıklaması

DayBreach CVE AI Araştırması

CVE-2016-8735 için toplanan üretici, dağıtım, yama ve güvenlik kaynağı kayıtlarını karşılaştırıp kanıt bağlantılı bir açıklama hazırlayalım.

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

IMPACT — Etkilenen Ürünler ve Yazılımlar

Affected Products

The following products are affected by CVE-2016-8735 vulnerability. Even if our threat engine is aware of the exact versions of the products that are affected, the information is represented below.

IDVENDORPRODUCTACTION
1apachetomcat İncele
2apachetomcat İncele
3apachetomcat İncele
4apachetomcat İncele
5apachetomcat İncele
6canonicalubuntu linux İncele
7netapp7-mode transition tool İncele
8netapponcommand insight İncele
9netapponcommand shift İncele
10netappsnap creator framework İncele
11debiandebian linux İncele
12redhatjboss enterprise web server İncele
13oracleagile engineering data management İncele
14oracleagile engineering data management İncele
15oracleagile engineering data management İncele
16oracleagile product lifecycle management İncele
17oracleagile product lifecycle management İncele
18oraclecommunications application session controller İncele
19oraclecommunications application session controller İncele
20oraclecommunications instant messaging server İncele
21oraclecommunications interactive session recorder İncele
22oraclecommunications interactive session recorder İncele
23oraclecommunications interactive session recorder İncele
24oraclehospitality guest access İncele
25oraclehospitality guest access İncele
26oraclemicros relate crm software İncele
27oraclemicros relate crm software İncele
28oraclemicros retail xbri loss prevention İncele
29oraclemicros retail xbri loss prevention İncele
30oraclemicros retail xbri loss prevention İncele
31oraclemicros retail xbri loss prevention İncele
32oraclemicros retail xbri loss prevention İncele
33oraclemicros retail xbri loss prevention İncele
34oraclemysql enterprise monitor İncele
35oraclemysql enterprise monitor İncele
36oraclemysql enterprise monitor İncele
37oracleretail convenience and fuel pos software İncele
38oracletransportation management İncele
39oracletransportation management İncele
40oracletransportation management İncele
41oracletransportation management İncele
42oracletransportation management İncele
43oracletransportation management İncele
44oracletransportation management İncele
45oracletransportation management İncele
46Red Hatred_hat_jboss_enterprise_web_server_2:tomcat6 İncele
47Red Hatred_hat_jboss_enterprise_web_server_2:tomcat6-admin-webapps İncele
48Red Hatred_hat_jboss_enterprise_web_server_2:tomcat6-docs-webapp İncele
49Red Hatred_hat_jboss_enterprise_web_server_2:tomcat6-el-1.0-api İncele
50Red Hatred_hat_jboss_enterprise_web_server_2:tomcat6-el-2.1-api İncele
51Red Hatred_hat_jboss_enterprise_web_server_2:tomcat6-javadoc İncele
52Red Hatred_hat_jboss_enterprise_web_server_2:tomcat6-jsp-2.1-api İncele
53Red Hatred_hat_jboss_enterprise_web_server_2:tomcat6-lib İncele
54Red Hatred_hat_jboss_enterprise_web_server_2:tomcat6-log4j İncele
55Red Hatred_hat_jboss_enterprise_web_server_2:tomcat6-maven-devel İncele
56Red Hatred_hat_jboss_enterprise_web_server_2:tomcat6-servlet-2.5-api İncele
57Red Hatred_hat_jboss_enterprise_web_server_2:tomcat6-webapps İncele
58Red Hatred_hat_jboss_enterprise_web_server_2:tomcat6.src İncele
59Red Hatred_hat_jboss_enterprise_web_server_2:tomcat7 İncele
60Red Hatred_hat_jboss_web_server_3:tomcat7 İncele
61Red Hatred_hat_jboss_web_server_3:tomcat8 İncele
62Red Hat6Server-JWS-3.1:hibernate4-c3p0-eap6-0:4.2.23-1.Final_redhat_1.1.ep6.el6.noarch İncele
63Red Hat6Server-JWS-3.1:hibernate4-core-eap6-0:4.2.23-1.Final_redhat_1.1.ep6.el6.noarch İncele
64Red Hat6Server-JWS-3.1:hibernate4-eap6-0:4.2.23-1.Final_redhat_1.1.ep6.el6.noarch İncele
65Red Hat6Server-JWS-3.1:hibernate4-eap6-0:4.2.23-1.Final_redhat_1.1.ep6.el6.src İncele
66Red Hat6Server-JWS-3.1:hibernate4-entitymanager-eap6-0:4.2.23-1.Final_redhat_1.1.ep6.el6.noarch İncele
67Red Hat6Server-JWS-3.1:hibernate4-envers-eap6-0:4.2.23-1.Final_redhat_1.1.ep6.el6.noarch İncele
68Red Hat6Server-JWS-3.1:jbcs-httpd24-apache-commons-daemon-0:1.0.15-1.redhat_2.1.jbcs.el6.noarch İncele
69Red Hat6Server-JWS-3.1:jbcs-httpd24-apache-commons-daemon-jsvc-1:1.0.15-17.redhat_2.jbcs.el6.i686 İncele
70Red Hat6Server-JWS-3.1:jbcs-httpd24-apache-commons-daemon-jsvc-debuginfo-1:1.0.15-17.redhat_2.jbcs.el6.i686 İncele
71Red Hat6Server-JWS-3.1:jbcs-httpd24-runtime-0:1-3.jbcs.el6.noarch İncele
72Red Hat6Server-JWS-3.1:mod_cluster-0:1.3.5-2.Final_redhat_2.1.ep7.el6.noarch İncele
73Red Hat6Server-JWS-3.1:mod_cluster-0:1.3.5-2.Final_redhat_2.1.ep7.el6.src İncele
74Red Hat6Server-JWS-3.1:mod_cluster-tomcat7-0:1.3.5-2.Final_redhat_2.1.ep7.el6.noarch İncele
75Red Hat6Server-JWS-3.1:mod_cluster-tomcat8-0:1.3.5-2.Final_redhat_2.1.ep7.el6.noarch İncele
76Red Hat6Server-JWS-3.1:tomcat-native-0:1.2.8-9.redhat_9.ep7.el6.i686 İncele
77Red Hat6Server-JWS-3.1:tomcat-native-0:1.2.8-9.redhat_9.ep7.el6.src İncele
78Red Hat6Server-JWS-3.1:tomcat-native-0:1.2.8-9.redhat_9.ep7.el6.x86_64 İncele
79Red Hat6Server-JWS-3.1:tomcat-native-debuginfo-0:1.2.8-9.redhat_9.ep7.el6.i686 İncele
80Red Hat6Server-JWS-3.1:tomcat-native-debuginfo-0:1.2.8-9.redhat_9.ep7.el6.x86_64 İncele
81Red Hat6Server-JWS-3.1:tomcat-vault-0:1.0.8-9.Final_redhat_2.1.ep7.el6.noarch İncele
82Red Hat6Server-JWS-3.1:tomcat-vault-0:1.0.8-9.Final_redhat_2.1.ep7.el6.src İncele
83Red Hat6Server-JWS-3.1:tomcat7-0:7.0.70-16.ep7.el6.noarch İncele
84Red Hat6Server-JWS-3.1:tomcat7-0:7.0.70-16.ep7.el6.src İncele
85Red Hat6Server-JWS-3.1:tomcat7-admin-webapps-0:7.0.70-16.ep7.el6.noarch İncele
86Red Hat6Server-JWS-3.1:tomcat7-docs-webapp-0:7.0.70-16.ep7.el6.noarch İncele
87Red Hat6Server-JWS-3.1:tomcat7-el-2.2-api-0:7.0.70-16.ep7.el6.noarch İncele
88Red Hat6Server-JWS-3.1:tomcat7-javadoc-0:7.0.70-16.ep7.el6.noarch İncele
89Red Hat6Server-JWS-3.1:tomcat7-jsp-2.2-api-0:7.0.70-16.ep7.el6.noarch İncele
90Red Hat6Server-JWS-3.1:tomcat7-jsvc-0:7.0.70-16.ep7.el6.noarch İncele
91Red Hat6Server-JWS-3.1:tomcat7-lib-0:7.0.70-16.ep7.el6.noarch İncele
92Red Hat6Server-JWS-3.1:tomcat7-log4j-0:7.0.70-16.ep7.el6.noarch İncele
93Red Hat6Server-JWS-3.1:tomcat7-selinux-0:7.0.70-16.ep7.el6.noarch İncele
94Red Hat6Server-JWS-3.1:tomcat7-servlet-3.0-api-0:7.0.70-16.ep7.el6.noarch İncele
95Red Hat6Server-JWS-3.1:tomcat7-webapps-0:7.0.70-16.ep7.el6.noarch İncele
96Red Hat6Server-JWS-3.1:tomcat8-0:8.0.36-17.ep7.el6.noarch İncele
97Red Hat6Server-JWS-3.1:tomcat8-0:8.0.36-17.ep7.el6.src İncele
98Red Hat6Server-JWS-3.1:tomcat8-admin-webapps-0:8.0.36-17.ep7.el6.noarch İncele
99Red Hat6Server-JWS-3.1:tomcat8-docs-webapp-0:8.0.36-17.ep7.el6.noarch İncele
100Red Hat6Server-JWS-3.1:tomcat8-el-2.2-api-0:8.0.36-17.ep7.el6.noarch İncele
101Red Hat6Server-JWS-3.1:tomcat8-javadoc-0:8.0.36-17.ep7.el6.noarch İncele
102Red Hat6Server-JWS-3.1:tomcat8-jsp-2.3-api-0:8.0.36-17.ep7.el6.noarch İncele
103Red Hat6Server-JWS-3.1:tomcat8-jsvc-0:8.0.36-17.ep7.el6.noarch İncele
104Red Hat6Server-JWS-3.1:tomcat8-lib-0:8.0.36-17.ep7.el6.noarch İncele
105Red Hat6Server-JWS-3.1:tomcat8-log4j-0:8.0.36-17.ep7.el6.noarch İncele
106Red Hat6Server-JWS-3.1:tomcat8-selinux-0:8.0.36-17.ep7.el6.noarch İncele
107Red Hat6Server-JWS-3.1:tomcat8-servlet-3.1-api-0:8.0.36-17.ep7.el6.noarch İncele
108Red Hat6Server-JWS-3.1:tomcat8-webapps-0:8.0.36-17.ep7.el6.noarch İncele
109Red Hat7Server-JWS-3.1:hibernate4-c3p0-eap6-0:4.2.23-1.Final_redhat_1.1.ep6.el7.noarch İncele
110Red Hat7Server-JWS-3.1:hibernate4-core-eap6-0:4.2.23-1.Final_redhat_1.1.ep6.el7.noarch İncele
111Red Hat7Server-JWS-3.1:hibernate4-eap6-0:4.2.23-1.Final_redhat_1.1.ep6.el7.noarch İncele
112Red Hat7Server-JWS-3.1:hibernate4-eap6-0:4.2.23-1.Final_redhat_1.1.ep6.el7.src İncele
113Red Hat7Server-JWS-3.1:hibernate4-entitymanager-eap6-0:4.2.23-1.Final_redhat_1.1.ep6.el7.noarch İncele
114Red Hat7Server-JWS-3.1:hibernate4-envers-eap6-0:4.2.23-1.Final_redhat_1.1.ep6.el7.noarch İncele
115Red Hat7Server-JWS-3.1:jbcs-httpd24-apache-commons-daemon-0:1.0.15-1.redhat_2.1.jbcs.el7.noarch İncele
116Red Hat7Server-JWS-3.1:jbcs-httpd24-apache-commons-daemon-jsvc-1:1.0.15-17.redhat_2.jbcs.el7.src İncele
117Red Hat7Server-JWS-3.1:jbcs-httpd24-apache-commons-daemon-jsvc-debuginfo-1:1.0.15-17.redhat_2.jbcs.el7.x86_64 İncele
118Red Hat7Server-JWS-3.1:jbcs-httpd24-runtime-0:1-3.jbcs.el7.noarch İncele
119Red Hat7Server-JWS-3.1:mod_cluster-0:1.3.5-2.Final_redhat_2.1.ep7.el7.noarch İncele
120Red Hat7Server-JWS-3.1:mod_cluster-0:1.3.5-2.Final_redhat_2.1.ep7.el7.src İncele
121Red Hat7Server-JWS-3.1:mod_cluster-tomcat7-0:1.3.5-2.Final_redhat_2.1.ep7.el7.noarch İncele
122Red Hat7Server-JWS-3.1:mod_cluster-tomcat8-0:1.3.5-2.Final_redhat_2.1.ep7.el7.noarch İncele
123Red Hat7Server-JWS-3.1:tomcat-native-0:1.2.8-9.redhat_9.ep7.el7.src İncele
124Red Hat7Server-JWS-3.1:tomcat-native-0:1.2.8-9.redhat_9.ep7.el7.x86_64 İncele
125Red Hat7Server-JWS-3.1:tomcat-native-debuginfo-0:1.2.8-9.redhat_9.ep7.el7.x86_64 İncele
126Red Hat7Server-JWS-3.1:tomcat-vault-0:1.0.8-9.Final_redhat_2.1.ep7.el7.noarch İncele
127Red Hat7Server-JWS-3.1:tomcat-vault-0:1.0.8-9.Final_redhat_2.1.ep7.el7.src İncele
128Red Hat7Server-JWS-3.1:tomcat7-0:7.0.70-16.ep7.el7.noarch İncele
129Red Hat7Server-JWS-3.1:tomcat7-0:7.0.70-16.ep7.el7.src İncele
130Red Hat7Server-JWS-3.1:tomcat7-admin-webapps-0:7.0.70-16.ep7.el7.noarch İncele
131Red Hat7Server-JWS-3.1:tomcat7-docs-webapp-0:7.0.70-16.ep7.el7.noarch İncele
132Red Hat7Server-JWS-3.1:tomcat7-el-2.2-api-0:7.0.70-16.ep7.el7.noarch İncele
133Red Hat7Server-JWS-3.1:tomcat7-javadoc-0:7.0.70-16.ep7.el7.noarch İncele
134Red Hat7Server-JWS-3.1:tomcat7-jsp-2.2-api-0:7.0.70-16.ep7.el7.noarch İncele
135Red Hat7Server-JWS-3.1:tomcat7-jsvc-0:7.0.70-16.ep7.el7.noarch İncele
136Red Hat7Server-JWS-3.1:tomcat7-lib-0:7.0.70-16.ep7.el7.noarch İncele
137Red Hat7Server-JWS-3.1:tomcat7-log4j-0:7.0.70-16.ep7.el7.noarch İncele
138Red Hat7Server-JWS-3.1:tomcat7-selinux-0:7.0.70-16.ep7.el7.noarch İncele
139Red Hat7Server-JWS-3.1:tomcat7-servlet-3.0-api-0:7.0.70-16.ep7.el7.noarch İncele
140Red Hat7Server-JWS-3.1:tomcat7-webapps-0:7.0.70-16.ep7.el7.noarch İncele
141Red Hat7Server-JWS-3.1:tomcat8-0:8.0.36-17.ep7.el7.noarch İncele
142Red Hat7Server-JWS-3.1:tomcat8-0:8.0.36-17.ep7.el7.src İncele
143Red Hat7Server-JWS-3.1:tomcat8-admin-webapps-0:8.0.36-17.ep7.el7.noarch İncele
144Red Hat7Server-JWS-3.1:tomcat8-docs-webapp-0:8.0.36-17.ep7.el7.noarch İncele
145Red Hat7Server-JWS-3.1:tomcat8-el-2.2-api-0:8.0.36-17.ep7.el7.noarch İncele
146Red Hat7Server-JWS-3.1:tomcat8-javadoc-0:8.0.36-17.ep7.el7.noarch İncele
147Red Hat7Server-JWS-3.1:tomcat8-jsp-2.3-api-0:8.0.36-17.ep7.el7.noarch İncele
148Red Hat7Server-JWS-3.1:tomcat8-jsvc-0:8.0.36-17.ep7.el7.noarch İncele
149Red Hat7Server-JWS-3.1:tomcat8-lib-0:8.0.36-17.ep7.el7.noarch İncele
150Red Hat7Server-JWS-3.1:tomcat8-log4j-0:8.0.36-17.ep7.el7.noarch İncele
151Red Hat7Server-JWS-3.1:tomcat8-selinux-0:8.0.36-17.ep7.el7.noarch İncele
152Red Hat7Server-JWS-3.1:tomcat8-servlet-3.1-api-0:8.0.36-17.ep7.el7.noarch İncele
153Red Hat7Server-JWS-3.1:tomcat8-webapps-0:8.0.36-17.ep7.el7.noarch İncele
154Red HatRed Hat JBoss Web Server 3.1 İncele
155apachetomcat İncele
Total Affected Vendor: 7|Products: 155

RED HAT CSAF/VEX — Ürün Etki Kontrolü

Bu CVE benim Red Hat ürünümü etkiliyor mu?

Sonuçlar doğrudan Red Hat CSAF VEX ürün durumundan gelir; tahmin değildir.

Düzeltme yayımlandı

Bu ürün dalı için Red Hat düzeltmesi yayımlanmış.

SCORING — CVSS Çoklu Kaynak Skoru

CVSS Scores

The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and display CVSS scores from various sources for each CVE.

SCOREVERSIONSEVERITYVECTORSOURCE
9.8CVSS V31CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HNVD
8.1cvss_v3HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HRed Hat
7.5CVSS V2—AV:N/AC:L/Au:N/C:P/I:P/A:PNVD
6.8cvss_v2—AV:N/AC:M/Au:N/C:P/I:P/A:PRed Hat

Yama ve İyileştirme Rehberi (Solution)

Solution & Remediation Advisory

Kısmi yama

50 düzeltme kanıtı bulundu; en az 16 ürün veya sürüm hâlâ etkileniyor ya da inceleniyor.

redhat

Before applying the update, back up your existing Red Hat JBoss Web Server installation (including all applications and configuration files). For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically.

Kaynağı aç
redhat

Before applying the update, back up your existing Red Hat JBoss Web Server installation (including all applications and configuration files). For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically.

Kaynağı aç
redhat

Before applying the update, back up your existing Red Hat JBoss Web Server installation (including all applications and configuration files). The References section of this erratum contains a download link (you must log in to download the update).

Kaynağı aç
redhat

Will not fix

nvd

NVD tarafından Patch olarak etiketlenmiş referans

Kaynağı aç
nvd

NVD tarafından Patch olarak etiketlenmiş referans

Kaynağı aç
nvd

NVD tarafından Patch olarak etiketlenmiş referans

Kaynağı aç
nvd

NVD tarafından Patch olarak etiketlenmiş referans

Kaynağı aç
nvd

NVD tarafından Patch olarak etiketlenmiş referans

Kaynağı aç
nvd

NVD tarafından Patch olarak etiketlenmiş referans

Kaynağı aç
nvd

NVD tarafından Patch olarak etiketlenmiş referans

Kaynağı aç
nvd

NVD tarafından Patch olarak etiketlenmiş referans

Kaynağı aç
Etkilenen ürün ve sürümü yukarıdaki kaynak kanıtlarıyla doğrulayın.
İnternete açık servislerde erişimi kısıtlayın ve ağ segmentasyonu uygulayın.
Kanıtta belirtilen resmî güncellemeyi yalnızca eşleşen ürün ve sürüme uygulayın.
Sunucu günlüklerini ve ağ uçlarını anormal çalıştırma belirtileri için izleyin.

Public exploit ve aktif sömürü durumu

Doğrulanmış exploit istihbaratı

Bu CVE CISA KEV kataloğunda aktif sömürülen olarak işaretli; ancak henüz doğrulanmış, indirilebilir bir public PoC veya Metasploit modülü bulunamadı. Aktif sömürü kanıtı public exploit kodu bulunduğu anlamına gelmez.

Zafiyet Dağılımı ve Saldırı Kalıpları (CWE & CAPEC)

CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2016-8735 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2016-8735 weaknesses.

Saldırı Vektörü ve Erişilebilirlik Karakteristiği

ErişimAğ üzerinden
YetkiGerekmiyor
KullanıcıGerekmiyor

Resmi Kaynaklar ve Danışma Bültenleri

CVSS Vektör Radar Grafiği

9.8 / 10
Attack VectorNetworkComplexityLowPrivilegesNoneUser Interact.NoneConfidentialityLowIntegrityNoneAvailabilityHigh

Vulnerability Scoring Details

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNetwork (Ağ)
Attack ComplexityLow (Düşük)
Privileges RequiredNone (Gerekmiyor)
User InteractionNone (Gerekmiyor)
Confidentiality (Gizlilik)Low (Düşük)
Integrity (Bütünlük)None (Yok)
Availability (Erişilebilirlik)High (Yüksek)

Kısmi yama

50 düzeltme kanıtı bulundu; en az 16 ürün veya sürüm hâlâ etkileniyor ya da inceleniyor.

Üreticiyi takip et

A
apache logo
apache
C
canonical logo
canonical
N
netapp logo
netapp
D
debian logo
debian
R
redhat logo
redhat
O
oracle logo
oracle

Zafiyet Türü (CWE & CAPEC)

İlgili Benzer Açıklar

Bu açığı API ile alın

Etkilenen ürünler, sürüm aralıkları, istismar durumu ve yama bilgisi tek istekte; ücretsiz anahtarla.

curl -H "x-api-key: $DAYBREACH_API_KEY" \
  "https://api.enginteksut.com.tr/api/v1/intel/cves/CVE-2016-8735"