CRITICAL9.8
GHSA-cw54-59pw-4g8c
Apache Tomcat Improper Access Control vulnerability
Quick fix
GHSA-cw54-59pw-4g8c — org.apache.tomcat:tomcat-catalina-jmx-remote: upgrade to the fixed version with the command below.
# pom.xml: bump <version>6.0.48</version> for org.apache.tomcat:tomcat-catalina-jmx-remoteDetails
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.tomcat:tomcat-catalina-jmx-remote
Introduced in:
0Fixed in: 6.0.48Fix
# pom.xml: bump <version>6.0.48</version> for org.apache.tomcat:tomcat-catalina-jmx-remoteMaven/org.apache.tomcat:tomcat-catalina-jmx-remote
Introduced in:
7.0.0Fixed in: 7.0.73Fix
# pom.xml: bump <version>7.0.73</version> for org.apache.tomcat:tomcat-catalina-jmx-remoteMaven/org.apache.tomcat:tomcat-catalina-jmx-remote
Introduced in:
8.0.0Fixed in: 8.0.39Fix
# pom.xml: bump <version>8.0.39</version> for org.apache.tomcat:tomcat-catalina-jmx-remoteMaven/org.apache.tomcat:tomcat-catalina-jmx-remote
Introduced in:
8.5.0Fixed in: 8.5.7Fix
# pom.xml: bump <version>8.5.7</version> for org.apache.tomcat:tomcat-catalina-jmx-remoteMaven/org.apache.tomcat:tomcat-catalina-jmx-remote
Introduced in:
9.0.0.M1Fixed in: 9.0.0.M12Fix
# pom.xml: bump <version>9.0.0.M12</version> for org.apache.tomcat:tomcat-catalina-jmx-remoteMaven/org.apache.tomcat:tomcat-catalina
Introduced in:
0Fixed in: 6.0.48Fix
# pom.xml: bump <version>6.0.48</version> for org.apache.tomcat:tomcat-catalinaMaven/org.apache.tomcat:tomcat-catalina
Introduced in:
7.0.0Fixed in: 7.0.73Fix
# pom.xml: bump <version>7.0.73</version> for org.apache.tomcat:tomcat-catalinaMaven/org.apache.tomcat:tomcat-catalina
Introduced in:
8.0.0Fixed in: 8.0.39Fix
# pom.xml: bump <version>8.0.39</version> for org.apache.tomcat:tomcat-catalinaMaven/org.apache.tomcat:tomcat-catalina
Introduced in:
8.5.0Fixed in: 8.5.7Fix
# pom.xml: bump <version>8.5.7</version> for org.apache.tomcat:tomcat-catalinaMaven/org.apache.tomcat:tomcat-catalina
Introduced in:
9.0.0.M1Fixed in: 9.0.0.M12Fix
# pom.xml: bump <version>9.0.0.M12</version> for org.apache.tomcat:tomcat-catalinaReferences
- https://nvd.nist.gov/vuln/detail/CVE-2016-8735[ADVISORY]
- https://github.com/apache/tomcat/commit/0e83ad3e547fc9a75a258799ef581249b40a82a6[WEB]
- https://github.com/apache/tomcat/commit/292d6ccdc9edbf80859929b0af070b2ea99fa688[WEB]
- https://github.com/apache/tomcat/commit/7e3a037055cca4a17e90b49399fb1bab4dd7c821[WEB]
- https://github.com/apache/tomcat80/commit/0f76016a4ec45635e450ada9c84ff7ee0c5f3799[WEB]
- https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc@%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95@%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb@%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c@%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b@%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E[WEB]
- https://security.netapp.com/advisory/ntap-20180607-0001[WEB]
- https://usn.ubuntu.com/4557-1[WEB]
- https://web.archive.org/web/20170423095340/http://www.securityfocus.com/bid/94463[WEB]
- https://web.archive.org/web/20170928203901/http://www.securitytracker.com/id/1037331[WEB]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-8735[WEB]
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html[WEB]
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html[WEB]
- https://access.redhat.com/errata/RHSA-2017:0455[WEB]
- https://access.redhat.com/errata/RHSA-2017:0456[WEB]
- https://github.com/apache/tomcat[PACKAGE]
- https://github.com/search?q=repo%3Aapache%2Ftomcat+catalina.mbeans+path%3A%2F%5Eres%5C%2Fbnd%5C%2F%2F&type=code[WEB]
- https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551@%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113@%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708@%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b@%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7@%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3@%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424@%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a@%3Cdev.tomcat.apache.org%3E[WEB]
- http://rhn.redhat.com/errata/RHSA-2017-0457.html[WEB]
- http://seclists.org/oss-sec/2016/q4/502[WEB]
- http://svn.apache.org/viewvc?view=revision&revision=1767644[WEB]
- http://svn.apache.org/viewvc?view=revision&revision=1767656[WEB]
- http://svn.apache.org/viewvc?view=revision&revision=1767676[WEB]
- http://svn.apache.org/viewvc?view=revision&revision=1767684[WEB]
- http://tomcat.apache.org/security-6.html[WEB]
- http://tomcat.apache.org/security-7.html[WEB]
- http://tomcat.apache.org/security-8.html[WEB]
- http://tomcat.apache.org/security-9.html[WEB]
- http://www.debian.org/security/2016/dsa-3738[WEB]
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html[WEB]
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html[WEB]
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html[WEB]
- http://www.securityfocus.com/bid/94463[WEB]
- http://www.securitytracker.com/id/1037331[WEB]