Evidence dossier

CVE-2016-8735

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if…

Exploited in the wild (CISA KEV since May 12, 2023). NVD reports CVSS 3.1 9.8. EPSS estimates 90.3% exploit likelihood as of Aug 26, 2026.

93.293.5Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

State
PUBLISHED
Published
Apr 6, 2017
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    apache

    Record text: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

    Inspect raw assertion
    Field
    container
    Value
    Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Apache Tomcat Remote Code Execution Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Apache Tomcat Remote Code Execution Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 90.34% probability · 99.79th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.903380000000; percentile 0.997880000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date May 12, 2023 · first observed Jul 19, 2026

Exploit likelihood90.34%

FIRST EPSS · score date Aug 26, 2026 · 99.8th percentile · first observed Aug 26, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

apacheOriginal assertion
Record text

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

Inspect raw assertion
Field
container
Value
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Apache Tomcat Remote Code Execution Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Apache Tomcat Remote Code Execution Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

90.34% probability · 99.79th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.903380000000; percentile 0.997880000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
56Underlying assertions
19Canonical products
56Target assertions
0Constraint assertions

Grouped from 6 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

20 scope groups

apache · source assertedApache Software FoundationApache TomcatDirect source scope
Affected: before 6.0.48Affected: 7.x before 7.0.73Affected: 8.x before 8.0.39Affected: 8.5.x before 8.5.7Affected: 9.x before 9.0.0.M12
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "before 6.0.48"}, {"status": "affected", "version": "7.x before 7.0.73"}, {"status": "affected", "version": "8.x before 8.0.39"}, {"status": "affected", "version": "8.5.x before 8.5.7"}, {"status": "affected", "version": "9.x before 9.0.0.M12"}]
NVD CPE · APPLICATIONapachetomcatVulnerable target · 16 assertions
Any version (unconstrained) (< 6.0.48); Any version (unconstrained) (>= 7.0.0, < 7.0.73); Any version (unconstrained) (>= 8.0, < 8.0.39); Any version (unconstrained) (>= 8.5.0, < 8.5.7); Version 9.0.0Canonical identity product-b4642eb973ddbe1a3e24c089bf036c528ab40d12c3eab0fae6fd551615375441Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:apache:tomcat:9.0.0:milestone2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9f542e12-6ba8-4504-a494-da83e7e19bd5
  2. cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 8.0; through excluding 8.0.39
    Match ID
    fbc4f54a-f99a-4b1a-aae4-0c64950c118d
  3. cpe:2.3:a:apache:tomcat:9.0.0:milestone4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d1902d2e-1896-4d3d-9e1c-3a675255072c
  4. cpe:2.3:a:apache:tomcat:9.0.0:milestone6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    454211d0-60a2-4661-aeca-4c0121413feb
  5. cpe:2.3:a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8b6787b6-54a8-475e-ba1c-ab99334b2535
  6. cpe:2.3:a:apache:tomcat:9.0.0:milestone3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c0c5f004-f7d8-45db-b173-351c50b0ec16
  7. cpe:2.3:a:apache:tomcat:9.0.0:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    67bbbd83-e232-4198-9748-c512d9e0eedd
  8. cpe:2.3:a:apache:tomcat:9.0.0:milestone1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9d0689fe-4bc0-4f53-8c79-34b21f9b86c2
  9. cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 6.0.48
    Match ID
    bdab7e8f-98da-43f2-b2ae-f0c5f1581b4a
  10. cpe:2.3:a:apache:tomcat:9.0.0:milestone5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    49aaf4df-f61d-47a8-8788-a21e317a145d
  11. cpe:2.3:a:apache:tomcat:9.0.0:milestone8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    558703ae-db5e-4dff-b497-c36694dd7b24
  12. cpe:2.3:a:apache:tomcat:9.0.0:milestone9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ed6273f2-1165-47a4-8dd7-9e9b2472941b
  13. cpe:2.3:a:apache:tomcat:9.0.0:milestone7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0686f977-889f-4960-8e0b-7784b73a7f2d
  14. cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 7.0.0; through excluding 7.0.73
    Match ID
    39ab06bf-6948-44fa-ae78-cdef64d7b771
  15. cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 8.5.0; through excluding 8.5.7
    Match ID
    ee43e8ed-8c32-42af-a76f-8731c0f8de7d
  16. cpe:2.3:a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    89b129b2-fb6f-4ef9-bf12-e589a87996cf
NVD CPE · OPERATING SYSTEMcanonicalubuntu_linuxVulnerable target · 1 assertions
Version 16.04Canonical identity product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7a5301bf-1402-4be0-a0f8-69fbe79bc6d6
NVD CPE · OPERATING SYSTEMdebiandebian_linuxVulnerable target · 1 assertions
Version 8.0Canonical identity product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c11e6fb0-c8c0-4527-9aa0-cb9b316f8f43
NVD CPE · APPLICATIONnetapp7-mode_transition_toolVulnerable target · 1 assertions
Version not applicableCanonical identity product-2474a13fdd73f8097e600be30594736ae4ce2d646b2742a055217b2b25d84d40Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:netapp:7-mode_transition_tool:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7ef6650c-558d-45c8-ae7d-136ee70cb6d7
NVD CPE · APPLICATIONnetapponcommand_insightVulnerable target · 1 assertions
Version not applicableCanonical identity product-6bac5e5dc0babe5d628e246786e711716ddfb068132218ad0dd5123beb466ec4Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f1be6c1f-2565-4e97-92aa-16563e5660a5
NVD CPE · APPLICATIONnetapponcommand_shiftVulnerable target · 1 assertions
Version not applicableCanonical identity product-96fd4aeba8f0231e1d0f6ca7ae786e70d484258209c2dd2c10b095c6d07c6180Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:netapp:oncommand_shift:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3bd81527-a341-42c3-9ab9-880d3db04b08
NVD CPE · APPLICATIONnetappsnap_creator_frameworkVulnerable target · 1 assertions
Version not applicableCanonical identity product-caaa8e228e72c153d0b12fb5994e6a4efe7929e90f7500b9c3dea5c9245a4b54Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:netapp:snap_creator_framework:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9f4754fb-e3eb-454a-ab1a-ae3835c5350c
NVD CPE · APPLICATIONoracleagile_engineering_data_managementVulnerable target · 3 assertions
Version 6.1.3; Version 6.2.0; Version 6.2.1.0Canonical identity product-9586a2db2c66a15d4bcf82ad70726953c6712a6ede02c9d1196a5346bf71a89eLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:agile_engineering_data_management:6.2.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1b21d189-0e7d-4878-91a0-be38a4aba1fd
  2. cpe:2.3:a:oracle:agile_engineering_data_management:6.1.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    61c5d278-11e5-4a2f-9860-6ffa579398cd
  3. cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    80c9dbb8-3d50-4d5d-859a-b022eb7c2e64
NVD CPE · APPLICATIONoracleagile_plmVulnerable target · 2 assertions
Version 9.3.5; Version 9.3.6Canonical identity product-61e478de61e41c69453ce682831f19e397da7c841b4f820e06d8d4a68fa2ec9bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c650fedb-e903-4c2d-ad40-282ab5f2e3c2
  2. cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ed43772f-d280-42f6-a292-7198284d6fe7
NVD CPE · APPLICATIONoraclecommunications_application_session_controllerVulnerable target · 2 assertions
Version 3.7.1; Version 3.8.0Canonical identity product-18ae55a70e75b97c340ecd3156617eb1cb06e6989a02b76b11c90939267c3975Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_application_session_controller:3.7.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cc967a48-d834-4e9b-8cec-057e7d5b8174
  2. cpe:2.3:a:oracle:communications_application_session_controller:3.8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f920cde4-df29-4611-93e9-a386c89edb62
NVD CPE · APPLICATIONoraclecommunications_instant_messaging_serverVulnerable target · 1 assertions
Version 10.0.1Canonical identity product-03e952e5feb49cbab6d67785e54883eca72c93fde4ee0531366703d67c7f92f5Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    622b95f1-8fa4-4aa6-9b68-5fe4302ba150
NVD CPE · APPLICATIONoraclecommunications_interactive_session_recorderVulnerable target · 3 assertions
Version 6.0; Version 6.1; Version 6.2Canonical identity product-cfe5d46cb1083fa06df42f506508992d8fbef448c68d6420b6889c47c808ab02Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_interactive_session_recorder:6.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bf0a211c-7c3d-46ae-b525-890a9194c422
  2. cpe:2.3:a:oracle:communications_interactive_session_recorder:6.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b1ad7c68-81df-4332-aeb3-b368e0221f52
  3. cpe:2.3:a:oracle:communications_interactive_session_recorder:6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c510ce66-dd71-45c8-b678-9bd81ec7ffbb
NVD CPE · APPLICATIONoraclehospitality_guest_accessVulnerable target · 2 assertions
Version 4.2.0; Version 4.2.1Canonical identity product-7744ccbcd8b62a3ac1f4418de6eb0aa032258e4ecfa917b191c1e0094cc6ca9bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e0f1df3e-0f2d-4efc-9a3e-f72149c8ae94
  2. cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1a3dc116-2844-47a1-bec2-d0675dd97148
NVD CPE · APPLICATIONoraclemicros_relate_crm_softwareVulnerable target · 2 assertions
Version 10.8; Version 11.4Canonical identity product-9d9fd48b619ab9b190e1dc39be13864e94665fe2cd99d87249aacde8b78c119eLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:micros_relate_crm_software:11.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ee3a1a04-5aae-40d9-842a-8b46211c5d95
  2. cpe:2.3:a:oracle:micros_relate_crm_software:10.8:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bde82f56-65b9-490b-8096-037add9819ab
NVD CPE · APPLICATIONoraclemicros_retail_xbri_loss_preventionVulnerable target · 6 assertions
Version 10.0.1; Version 10.5.0; Version 10.6.0; Version 10.7.7; Version 10.8.0; Version 10.8.1Canonical identity product-97b8db65c678f6a8f36811670c4d788f6a86e3041899c5a507c6cb04922f8b99Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    73c9a2ad-f384-44d5-ab33-86b7250760a5
  2. cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.8.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c1e3c86b-4483-430a-856d-7eab7d388d2e
  3. cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.0.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    78933dd0-f774-4e60-bc66-d5a57919717a
  4. cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.7.7:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cd8f1bf2-c047-4296-815b-b21a2a673dff
  5. cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.5.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8eca7a7e-8177-4fd4-b9b9-f4b1b6f43f98
  6. cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fa3f5761-e2a0-4f67-bae1-503877676bf3
NVD CPE · APPLICATIONoraclemysql_enterprise_monitorVulnerable target · 3 assertions
Any version (unconstrained) (<= 3.2.8.2223); Any version (unconstrained) (>= 3.3.0, <= 3.3.4.3247); Any version (unconstrained) (>= 3.4.0, <= 3.4.2.4181)Canonical identity product-57d551f18f44e8d3873b139bff1d5a2db2f13c717b3d0295e687bd95ab213facLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 21
    Logic
    OR
    Version bounds
    through including 3.2.8.2223
    Match ID
    cc2d40a0-f2f0-476c-959e-39ca64b430ed
  2. cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 22
    Logic
    OR
    Version bounds
    from including 3.3.0; through including 3.3.4.3247
    Match ID
    c992ccd1-54c9-4bc2-876f-7a5d76571dea
  3. cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 23
    Logic
    OR
    Version bounds
    from including 3.4.0; through including 3.4.2.4181
    Match ID
    bebb610e-4fe2-41c2-b3a3-d67077a60f82
NVD CPE · APPLICATIONoracleretail_convenience_and_fuel_pos_softwareVulnerable target · 1 assertions
Version 2.1.132Canonical identity product-f9c015ac515cb2a7cd7207205384914e8f81f0dcb6775b4c7aec3d75dee4389bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:retail_convenience_and_fuel_pos_software:2.1.132:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    da5b8931-d3b4-46a9-b1a0-9a6bba365fc8
NVD CPE · APPLICATIONoracletransportation_managementVulnerable target · 8 assertions
Version 6.3.0; Version 6.3.1; Version 6.3.2; Version 6.3.3; Version 6.3.4; Version 6.3.5; Version 6.3.6; Version 6.3.7Canonical identity product-9c24c965edf74248d6e6c4a32705790ac6aed2a1d1df28dd2620aa229124c509Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:transportation_management:6.3.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    48fe41ba-1e3c-4626-930f-3f8fee124a78
  2. cpe:2.3:a:oracle:transportation_management:6.3.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    835bb7d9-633c-4cb3-8e8f-ca6fd62e587a
  3. cpe:2.3:a:oracle:transportation_management:6.3.7:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a58642e0-ca59-4de6-a83c-f551fc621c32
  4. cpe:2.3:a:oracle:transportation_management:6.3.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a775321b-6dfb-4770-8f6d-d34d655438af
  5. cpe:2.3:a:oracle:transportation_management:6.3.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    40f284ef-05cf-4cf5-b7ca-f58ae01da3b6
  6. cpe:2.3:a:oracle:transportation_management:6.3.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    231ddd84-5af3-4f0d-81d8-da0f942e78f1
  7. cpe:2.3:a:oracle:transportation_management:6.3.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e7a714fb-050a-4040-bc57-c22fa4dd58d2
  8. cpe:2.3:a:oracle:transportation_management:6.3.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c09892e8-d580-488a-a80e-b358d682a25a
NVD CPE · APPLICATIONredhatjboss_enterprise_web_serverVulnerable target · 1 assertions
Version 3.0.0Canonical identity product-0f3c5d8c07e690c486e2e297e55bea9245b06546874f1021e18a5b6abda9f72aLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:redhat:jboss_enterprise_web_server:3.0.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8e2f2f98-db90-43f6-8f28-3656207b6188

Affected-product evidence

Accepted scope and product mapping

19 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-03e952e5feb49cbab6d67785e54883eca72c93fde4ee0531366703d67c7f92f5

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
71ae62fb-285e-404a-bccc-ebf86bed96bc
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-0f3c5d8c07e690c486e2e297e55bea9245b06546874f1021e18a5b6abda9f72a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c330a0fe-c6fa-459e-ad04-f7d7e109f577
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-18ae55a70e75b97c340ecd3156617eb1cb06e6989a02b76b11c90939267c3975

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3d351841-9f83-4194-bb54-223d0adc3a349230b4a9-8204-4df1-b51f-b908d20be194
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-2474a13fdd73f8097e600be30594736ae4ce2d646b2742a055217b2b25d84d40

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
739b0afb-4b3c-4eb2-a031-742a30564407
Mapping establishedEvidence supported

vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0e7a367e-3abd-44df-a8d5-1de717c3a6bb
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-57d551f18f44e8d3873b139bff1d5a2db2f13c717b3d0295e687bd95ab213fac

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7cc2a0eb-09d5-40e4-9fac-49d5a2185e77d6d693a3-33bd-427d-84b0-8f2bbeeced85f288e8ca-010d-490c-a4de-158f3929be06
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-61e478de61e41c69453ce682831f19e397da7c841b4f820e06d8d4a68fa2ec9b

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
922adb9f-0855-44d7-a001-0f0a098aed87aacff97c-12b0-4303-b855-6a0a6aaf90cb
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-6bac5e5dc0babe5d628e246786e711716ddfb068132218ad0dd5123beb466ec4

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
78fc22ca-7120-45d4-8ded-9b9f61c285fc
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-7744ccbcd8b62a3ac1f4418de6eb0aa032258e4ecfa917b191c1e0094cc6ca9b

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5fb3310d-31f2-40c7-b8d3-74130e091fe865b655b4-4df5-4073-936a-b3df8bb58959
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-9586a2db2c66a15d4bcf82ad70726953c6712a6ede02c9d1196a5346bf71a89e

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
04e252f9-4764-43d4-89f2-a47ab5a4dd2b34981ea4-cc0d-4d86-b546-03e1b93db6839648c61a-f7fd-4a14-9ce4-25c2c11dcb3e
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-96fd4aeba8f0231e1d0f6ca7ae786e70d484258209c2dd2c10b095c6d07c6180

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ce0c2227-a824-4bbc-a591-6189b5fb7cff
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-97b8db65c678f6a8f36811670c4d788f6a86e3041899c5a507c6cb04922f8b99

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0c9dd2a1-cedf-4b21-94f2-4cd9e0c8fec0711b24bd-36d4-4cd7-ae18-245f72bed4baa4c9d8b8-e054-4fdb-8bdb-a008aceb61f9b0ff99ed-6a20-439c-9197-d24c42b3df95daa1519e-5793-40b3-9f59-30e41d46b5fef8a443be-871b-43ed-b1f9-4480a0917409
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-9c24c965edf74248d6e6c4a32705790ac6aed2a1d1df28dd2620aa229124c509

Source class
Nvd cpe vulnerable target
Assertions
8
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
00d43366-deb9-48bb-8881-5a5cae7eca3a1345662e-af0f-4774-8135-d84ffa3c585b2037cb30-02f2-4b91-ba70-ef25b7a487103efe823a-4c9a-4a6b-9b4b-1540ed4fb5af52cda751-cd2a-43d3-80a0-ff211441f64b56b93c2a-0038-42b2-aa30-64aa6edbdec06d6581ab-9051-4ef6-9f8c-7defb7c90ad1934af9a8-2d56-4d9b-acd7-55a19522d2bc
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-9d9fd48b619ab9b190e1dc39be13864e94665fe2cd99d87249aacde8b78c119e

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f3789bac-92bd-4d43-94a8-7f1c875c75d6f9c5b81b-9e52-4ece-88d4-c1e061c4a496
Mapping establishedEvidence supported

vendor-c57a6167e95991f72f9616ac32b40463ac13c5f4929fcce3efc058b09a445b54 · product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
437ece0f-7d47-413c-a683-dbb07f4b34b9
Mapping establishedEvidence supported

vendor-8771dac0ae5eeec984ca23e4bbe5a243fb7896ad7c1c4afc6acd3abe53fdd152 · product-b4642eb973ddbe1a3e24c089bf036c528ab40d12c3eab0fae6fd551615375441

Source class
Nvd cpe vulnerable target
Assertions
16
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0adefb5b-de0e-492f-8e5d-9f01f08089990e26d0ca-c2a6-488f-8f05-6418c175d1240f834f81-80b4-4be3-8f50-3d1f8a8fba1b286e4012-1af1-44a5-a67f-214a9760aef454c3d3f5-f107-4ccb-9091-79405887e0306bcf5635-3caf-4cf7-b726-cc8b3cdfca016dc395eb-e878-458b-a14d-037dfb6dc35472045c7a-4651-4334-a872-4a32605c5bf57511088b-843a-41a9-8349-9904ac07fc107ecc76c0-3b1b-4504-b672-6995dca3e1f6805b33a2-c090-4c3c-8b12-e1a9cf3203599421478e-f77c-4044-b168-fd8c04ddde8fb364c97e-723b-456e-8ad0-0067e10e451dc1c852be-455b-4e67-aac9-39e37c2e1114dba64f4b-eb5e-4a3b-aa09-1dbd0aedeec3f206e12f-0305-407e-967e-b6666ddc6319
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-caaa8e228e72c153d0b12fb5994e6a4efe7929e90f7500b9c3dea5c9245a4b54

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3648fef4-605b-4601-a0ab-0b7c1e9ce921
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-cfe5d46cb1083fa06df42f506508992d8fbef448c68d6420b6889c47c808ab02

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
48a1d70e-6263-4fc6-8ca1-16755d777b68a9ba5030-99f0-4047-b0ef-d35d9bf6aedeba531486-d7e6-4861-b749-5aebc4b07da6
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-f9c015ac515cb2a7cd7207205384914e8f81f0dcb6775b4c7aec3d75dee4389b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1e6f0204-f84a-43e0-a578-561f35f53a34
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4d591559-65e8-4a3a-9c66-2029af7722b5

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:P/I:P/A:P
9.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

9.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
9.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.