critical Known exploitedREV. 01
CVE-2016-8735Apache Tomcat — a management listener left behind
Tomcat's remote management listener was never brought in line with an Oracle fix for credential handling, so an attacker who reaches the management ports runs code. It applies only where that listener is configured.
Read the risk
THE VITAL STATS- CVSS score
- 9.8/ 10 CVSS v3.1
- EPSS probability
- 90% Likelihood of exploitation
- Attack complexity
- Low Conditions needed to exploit
- Known exploited
- Yes — CISA KEV
- CVE published
- 2017-04-06
- Added to KEV
- 2023-05-12
- Exploit published
- Not recorded
- Confidence
- medium
- Kill chain
- initial access
- MITRE ATT&CK
- T1190
- Severity
- critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attacker needsThe remote management listener must be configured, and its ports reachable.
Fixed inApache Tomcat >= 6.0.48, Apache Tomcat >= 7.0.73, Apache Tomcat >= 8.0.39, Apache Tomcat >= 8.5.7, Apache Tomcat >= 9.0.0.M12
Behind the card
5 REFERENCES- 01CVE recordNVD recordnvd.nist.gov
- 02CISACISA Known Exploited Vulnerabilities catalogcisa.gov
- 03Vendor advisoryseclists.orgseclists.org
- 04Vendor advisorysvn.apache.orgsvn.apache.org
- 05Vendor advisorysvn.apache.orgsvn.apache.org
Field-level provenanceTRACE THE SOURCES +
Which source supports each field, when it was retrieved, and who extracted it.
| Fields | Source | Retrieved | Extractor | Confidence |
|---|---|---|---|---|
| cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_at | nvd.nist.gov | 2026-09-24 | scrty-crds-pipeline/0.1 | high |
| exploitation.known_exploited, exploitation.kev_added | cisa.gov | 2026-09-24 | scrty-crds-pipeline/0.1 | high |
| epss | api.first.org | 2026-09-24 | scrty-crds-pipeline/0.1 | high |
| title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisites | nvd.nist.gov | 2026-09-24 | claude-code | high |
Printing history
THE RECORD- r1Initial base card
First printing. This card has not been reprinted since publication.