{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2016-8735",
  "revision": 1,
  "title": "Apache Tomcat — a management listener left behind",
  "summary": "Tomcat's remote management listener was never brought in line with an Oracle fix for credential handling, so an attacker who reaches the management ports runs code. It applies only where that listener is configured.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.90338,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2023-05-12",
    "prerequisites": "The remote management listener must be configured, and its ports reachable."
  },
  "remediation": {
    "patch_available": true,
    "workaround_available": true,
    "fixed_in": [
      "Apache Tomcat >= 6.0.48",
      "Apache Tomcat >= 7.0.73",
      "Apache Tomcat >= 8.0.39",
      "Apache Tomcat >= 8.5.7",
      "Apache Tomcat >= 9.0.0.M12"
    ]
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Upgrade Tomcat to 6.0.48, 7.0.73, 8.0.39, 8.5.7 or 9.0.0.M12, or remove the remote management listener where nothing depends on it.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2016-8735",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2016-8735",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2016-8735",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-8735",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "http://seclists.org/oss-sec/2016/q4/502"
    },
    {
      "type": "vendor_advisory",
      "url": "http://svn.apache.org/viewvc?view=revision&revision=1767644"
    },
    {
      "type": "vendor_advisory",
      "url": "http://svn.apache.org/viewvc?view=revision&revision=1767656"
    }
  ],
  "published_at": "2017-04-06T21:59:00.243Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "apache",
    "tomcat",
    "jmx",
    "remote-code-execution",
    "java",
    "kev"
  ]
}
