Skip to main content
Question

Apache Vulnerability CVE-2016-8735

  • February 17, 2025
  • 4 replies
  • 109 views

Forum|alt.badge.img+13

This one is a bit of an old vulnerability and I see there has been an update to its status this month.

 

A customer has picked up this vulnerability on the Commserve. They’re running V11.28.102.

I cannot find any information on the security bulletin site. I’ve recommended that they upgrade to V11.28.137 as there is mention of some Apache vulnerability patches mentioned (but not which ones)and then run the vulnerability scanner.

 

Does anyone have any info or experience in this particular issue that we’ve noted?

 

 

4 replies

Rajiv
Vaulter
Forum|alt.badge.img+12
  • Vaulter
  • February 17, 2025

Hello ​@Mauro I would suggest you open a support ticket with us to get this investigated. 

Best,

Rajiv Singal


Forum|alt.badge.img+3

No version of Commvault was ever affected by CVE-2016-8735.

The earliest version of Tomcat 9.x we ever used (back in SP16 or so) was 9.0.12, and the CVE only affected old milestone releases of 9.0.0, per the CVE description.

If the customer still has concerns, they will need to open a ticket and provide details from their security audit.

 

 


Onno van den Berg
Community All Star
Forum|alt.badge.img+22

Funny to see that their vulnerability scanner found something vulnerable in Commvault version that is already more than a year old. I hope their scanning is part of a bigger project to improve their resilience, but leaving you environment unpatched for so long is waiting for a disaster to strike…..


Forum|alt.badge.img+13
  • Author
  • Novice
  • March 11, 2025

Thanks for the feedback all. I wasn’t available for a few weeks, hence my late response.

I will pass this feedback to the customer and log a ticket if they still have concerns.

I’ll provide feedback.