Back

CRITICAL KEV

tomcat: Remote code execution vulnerability in JmxRemoteLifecycleListener

Published Apr 6, 2017 ·Due Jun 2, 2023

Description

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (68)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Apr 6, 2017
Updated Oct 21, 2025
Reserved Oct 18, 2016
CISA Vulnrichment
Updated Feb 4, 2025
NVD
Status Analyzed
Modified Aug 25, 2026
Red Hat
Severity Important
Public date Nov 22, 2016
GHSA-CW54-59PW-4G8C