imPC@ndo EN

Tracker / CVE-2016-8735

CVE-2016-8735

Sfruttata Critica 9.8

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

Prodotti e versioni affette

apache tomcat
apache tomcat · … → 6.0.48
apache tomcat · 7.0.0 → 7.0.73
apache tomcat · 8.0 → 8.0.39
apache tomcat · 8.5.0 → 8.5.7
canonical ubuntu_linux
debian debian_linux
netapp 7-mode_transition_tool
netapp oncommand_insight
netapp oncommand_shift
netapp snap_creator_framework
oracle agile_engineering_data_management
oracle agile_plm
oracle communications_application_session_controller
oracle communications_instant_messaging_server
oracle communications_interactive_session_recorder
oracle hospitality_guest_access
oracle micros_relate_crm_software
oracle micros_retail_xbri_loss_prevention
oracle mysql_enterprise_monitor · … → 3.2.8.2223
oracle mysql_enterprise_monitor · 3.3.0 → 3.3.4.3247
oracle mysql_enterprise_monitor · 3.4.0 → 3.4.2.4181
oracle retail_convenience_and_fuel_pos_software
oracle transportation_management
redhat jboss_enterprise_web_server

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti