VYPR

Maven package

org.apache.tomcat/tomcat-catalina-jmx-remote

pkg:maven/org.apache.tomcat/tomcat-catalina-jmx-remote

Vulnerabilities (1)

  • CVE-2016-8735CriKEVApr 6, 2017
    affected < 6.0.48fixed 6.0.48

    Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated