8.1
CVE-2017-12617
- EPSS 94.37%
- Published 04.10.2017 01:29:02
- Last modified 20.04.2025 01:37:25
- Source security@apache.org
- Teams watchlist Login
- Open Login
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Data is provided by the National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version12.04 SwEditionesm
Canonical ≫ Ubuntu Linux Version16.04 SwEditionesm
Canonical ≫ Ubuntu Linux Version17.10
Canonical ≫ Ubuntu Linux Version18.04 SwEditionesm
Oracle ≫ Communications Instant Messaging Server Version10.0.1
Oracle ≫ Endeca Information Discovery Integrator Version3.1.0
Oracle ≫ Endeca Information Discovery Integrator Version3.2.0
Oracle ≫ Enterprise Manager For Mysql Database Version12.1.0.4.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 7.3.3.0.0 <= 7.3.5.3.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 8.0.0.0.0 <= 8.0.9.0.0
Oracle ≫ Fmw Platform Version12.2.1.2.0
Oracle ≫ Fmw Platform Version12.2.1.3.0
Oracle ≫ Health Sciences Empirica Inspections Version1.0.1.1
Oracle ≫ Hospitality Guest Access Version4.2.0
Oracle ≫ Hospitality Guest Access Version4.2.1
Oracle ≫ Instantis Enterprisetrack Version17.1
Oracle ≫ Instantis Enterprisetrack Version17.2
Oracle ≫ Management Pack Version11.2.1.0.13 SwPlatformgoldengate
Oracle ≫ Micros Lucas Version2.9.5
Oracle ≫ Micros Retail Xbri Loss Prevention Version10.0.1
Oracle ≫ Micros Retail Xbri Loss Prevention Version10.5.0
Oracle ≫ Micros Retail Xbri Loss Prevention Version10.6.0
Oracle ≫ Micros Retail Xbri Loss Prevention Version10.7.0
Oracle ≫ Micros Retail Xbri Loss Prevention Version10.8.0
Oracle ≫ Micros Retail Xbri Loss Prevention Version10.8.1
Oracle ≫ Mysql Enterprise Monitor Version <= 3.3.6.3293
Oracle ≫ Mysql Enterprise Monitor Version >= 3.4.0 <= 3.4.4.4226
Oracle ≫ Mysql Enterprise Monitor Version >= 4.0.0 <= 4.0.0.5135
Oracle ≫ Retail Advanced Inventory Planning Version13.2
Oracle ≫ Retail Advanced Inventory Planning Version13.4
Oracle ≫ Retail Advanced Inventory Planning Version14.1
Oracle ≫ Retail Advanced Inventory Planning Version15.0
Oracle ≫ Retail Back Office Version14.0.4
Oracle ≫ Retail Back Office Version14.1.3
Oracle ≫ Retail Central Office Version14.0.4
Oracle ≫ Retail Central Office Version14.1.3
Oracle ≫ Retail Convenience And Fuel Pos Software Version2.1.132
Oracle ≫ Retail Eftlink Version1.1.124
Oracle ≫ Retail Eftlink Version15.0.1
Oracle ≫ Retail Eftlink Version16.0.2
Oracle ≫ Retail Insights Version14.0
Oracle ≫ Retail Insights Version14.1
Oracle ≫ Retail Insights Version15.0
Oracle ≫ Retail Insights Version16.0
Oracle ≫ Retail Invoice Matching Version12.0
Oracle ≫ Retail Invoice Matching Version13.0
Oracle ≫ Retail Invoice Matching Version13.1
Oracle ≫ Retail Invoice Matching Version13.2
Oracle ≫ Retail Invoice Matching Version14.0
Oracle ≫ Retail Invoice Matching Version14.1
Oracle ≫ Retail Invoice Matching Version15.0
Oracle ≫ Retail Invoice Matching Version16.0
Oracle ≫ Retail Order Broker Version5.0
Oracle ≫ Retail Order Broker Version5.1
Oracle ≫ Retail Order Broker Version5.2
Oracle ≫ Retail Order Broker Version15.0
Oracle ≫ Retail Order Broker Version16.0
Oracle ≫ Retail Order Management System Version4.0
Oracle ≫ Retail Order Management System Version4.5
Oracle ≫ Retail Order Management System Version4.7
Oracle ≫ Retail Order Management System Version5.0
Oracle ≫ Retail Point-of-service Version14.0.4
Oracle ≫ Retail Point-of-service Version14.1.3
Oracle ≫ Retail Price Management Version12.0
Oracle ≫ Retail Price Management Version13.0
Oracle ≫ Retail Price Management Version13.1
Oracle ≫ Retail Price Management Version13.2
Oracle ≫ Retail Price Management Version14.0
Oracle ≫ Retail Price Management Version14.1
Oracle ≫ Retail Price Management Version15.0
Oracle ≫ Retail Price Management Version16.0
Oracle ≫ Retail Returns Management Version2.3.8
Oracle ≫ Retail Returns Management Version2.4.9
Oracle ≫ Retail Returns Management Version14.0.4
Oracle ≫ Retail Returns Management Version14.1.3
Oracle ≫ Retail Store Inventory Management Version12.0.12
Oracle ≫ Retail Store Inventory Management Version13.0.7
Oracle ≫ Retail Store Inventory Management Version13.1.9
Oracle ≫ Retail Store Inventory Management Version13.2.9
Oracle ≫ Retail Store Inventory Management Version14.0.4
Oracle ≫ Retail Store Inventory Management Version14.1.3
Oracle ≫ Retail Store Inventory Management Version15.0.2
Oracle ≫ Retail Store Inventory Management Version16.0.1
Oracle ≫ Retail Xstore Point Of Service Version6.0.11
Oracle ≫ Retail Xstore Point Of Service Version7.0.6
Oracle ≫ Retail Xstore Point Of Service Version7.1.6
Oracle ≫ Retail Xstore Point Of Service Version15.0.1
Oracle ≫ Transportation Management Version6.3.1
Oracle ≫ Transportation Management Version6.3.2
Oracle ≫ Transportation Management Version6.3.3
Oracle ≫ Transportation Management Version6.3.4
Oracle ≫ Transportation Management Version6.3.5
Oracle ≫ Transportation Management Version6.3.6
Oracle ≫ Transportation Management Version6.3.7
Oracle ≫ Tuxedo System And Applications Monitor Version12.1.3.0.0
Oracle ≫ Webcenter Sites Version11.1.1.8.0
Oracle ≫ Workload Manager Version12.2.0.1
Debian ≫ Debian Linux Version7.0
Netapp ≫ Active Iq Unified Manager SwPlatformwindows Version >= 7.3
Netapp ≫ Active Iq Unified Manager SwPlatformvmware_vsphere Version >= 9.5
Netapp ≫ Oncommand Balance Version-
Netapp ≫ Oncommand Insight Version-
Netapp ≫ Oncommand Shift Version-
Netapp ≫ Oncommand Workflow Automation Version-
Netapp ≫ Snapcenter Version-
Redhat ≫ Jboss Enterprise Application Platform Version6.0.0
Redhat ≫ Jboss Enterprise Application Platform Version6.4.0
Redhat ≫ Jboss Enterprise Web Server Version2.0.0
Redhat ≫ Jboss Enterprise Web Server Version3.0.0
Redhat ≫ Enterprise Linux Desktop Version6.0
Redhat ≫ Enterprise Linux Desktop Version7.0
Redhat ≫ Enterprise Linux Eus Version7.4
Redhat ≫ Enterprise Linux Eus Version7.5
Redhat ≫ Enterprise Linux Eus Version7.6
Redhat ≫ Enterprise Linux Eus Version7.7
Redhat ≫ Enterprise Linux Eus Compute Node Version7.4
Redhat ≫ Enterprise Linux Eus Compute Node Version7.5
Redhat ≫ Enterprise Linux Eus Compute Node Version7.6
Redhat ≫ Enterprise Linux Eus Compute Node Version7.7
Redhat ≫ Enterprise Linux For Ibm Z Systems Version6.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Version7.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version7.4_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version7.5_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version7.6_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version7.7_s390x
Redhat ≫ Enterprise Linux For Power Big Endian Version6.0_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Version7.0_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version7.4_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version7.5_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version7.6_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version7.7_ppc64
Redhat ≫ Enterprise Linux For Power Little Endian Version7.0
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version7.4_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version7.5_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version7.6_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version7.7_ppc64le
Redhat ≫ Enterprise Linux Server Version6.0
Redhat ≫ Enterprise Linux Server Version7.0
Redhat ≫ Enterprise Linux Server Aus Version7.4
Redhat ≫ Enterprise Linux Server Aus Version7.6
Redhat ≫ Enterprise Linux Server Aus Version7.7
Redhat ≫ Enterprise Linux Server Tus Version7.4
Redhat ≫ Enterprise Linux Server Tus Version7.6
Redhat ≫ Enterprise Linux Server Tus Version7.7
Redhat ≫ Enterprise Linux Workstation Version6.0
Redhat ≫ Enterprise Linux Workstation Version7.0
25.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Apache Tomcat Remote Code Execution Vulnerability
VulnerabilityWhen running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
DescriptionApply updates per vendor instructions.
Required actionsType | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 94.37% | 1 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.