Loading
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
Use Apache vendor hub and Tomcat product page to widen CVE-2016-8735 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-29145, CVE-2026-34487 and CVE-2026-34486 for nearby disclosures in the same product family.