Lucene search

K
redhatcveRedhat.comRH:CVE-2016-8735
HistoryJan 03, 2021 - 6:49 p.m.

CVE-2016-8735

2021-01-0318:49:05
redhat.com
access.redhat.com
77

0.251 Low

EPSS

Percentile

96.7%

The JmxRemoteLifecycleListener was not updated to take account of Oracle’s fix for CVE-2016-3427. JMXRemoteLifecycleListener is only included in EWS 2.x and JWS 3.x source distributions. If you deploy a Tomcat instance built from source, using the EWS 2.x, or JWS 3.x distributions, an attacker could use this flaw to launch a remote code execution attack on your deployed instance.