Vulnerability Intelligence

🛡 CVE-2016-8735

Apache Tomcat Remote Code Execution Vulnerability
Apache Tomcat CWE-284

Ransomware use

CISA KEV

EPSS

90.3%
Likely exploited · 100th pct

Added to KEV

2023-05-12
CISA

Remediate by

2023-06-02
⚠ OVERDUE

CWE

CWE-284
weakness

📈 EPSS exploit probability

90.3%
FIRST EPSS — 30-day probability of exploitation in the wild · band Likely exploited · higher than 100% of all scored CVEs

⚠ KEV remediation overdue

CISA required federal remediation by 2023-06-02. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.

📄 Description

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't up

🛡 Add to case

Attach CVE-2016-8735 (Vulnerability / CVE) and pull all linked entities:
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php