Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added CVE-2016-8735 Apache Tomcat JMX RCE template #11101

Closed

Conversation

aybanda
Copy link

@aybanda aybanda commented Oct 26, 2024

Template / PR Information

Add CVE-2016-8735 Apache Tomcat JMX RCE template

This PR adds a new Nuclei template to detect CVE-2016-8735, a remote code execution vulnerability in Apache Tomcat's JMX implementation.

  • Vulnerability: Apache Tomcat JMX Remote Code Execution
  • Affected versions: before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12
  • CVSS Score: 10 (Critical)

The template checks for vulnerable versions and the presence of JMXProxyServlet, indicating potential exposure to this vulnerability.

Template Validation

I've validated this template locally?

  • YES
  • NO
Screenshot 2024-10-27 at 12 53 26 AM

Additional Details

N/A

/claim #10893

Copy link

algora-pbc bot commented Oct 26, 2024

👉 To complete your submission, sign up on Algora, link your Github account and submit the data for your PR.

@GeorginaReeder
Copy link

Thanks so much for your contribution @aybanda ! :)

@ritikchaddha
Copy link
Contributor

Hi @aybanda,

Thank you for sharing this template! Currently, we are not accepting version-based templates. However, if you can provide a complete proof of concept (POC) along with exploitation information, please feel free to resubmit your bounty claim. We would be happy to review it.

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants