peter bassill · operator
$ cve CVE-2017-12617 JSON

CVE-2017-12617 KEV EXPLOIT

8.1
HIGH · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.97% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-434
On CISA KEVyes — remediate by 2022-04-15
Public exploityes
Published2017-10-04
Last modified2026-08-25

CISA KEV

NameApache Tomcat Remote Code Execution Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productApache / Tomcat
Ransomware usenone reported

Affected (40)

VendorProduct
apachetomcat
canonicalubuntu linux
debiandebian linux
netappactive iq unified manager
netapponcommand balance
netapponcommand insight
netapponcommand shift
netapponcommand workflow automation
netappsnapcenter
oracleagile product lifecycle management
oraclecommunications instant messaging server
oracleendeca information discovery integrator
oracleenterprise manager for mysql database
oraclefinancial services analytical applications infrastructure
oraclefmw platform
oraclehealth sciences empirica inspections
oraclehospitality guest access
oracleinstantis enterprisetrack
oraclemanagement pack
oraclemicros lucas
oraclemicros retail xbri loss prevention
oraclemysql enterprise monitor
oracleretail advanced inventory planning
oracleretail back office
oracleretail central office
oracleretail convenience and fuel pos software
oracleretail eftlink
oracleretail insights
oracleretail invoice matching
oracleretail order broker
oracleretail order management system
oracleretail point-of-service
oracleretail price management
oracleretail returns management
oracleretail store inventory management
oracleretail xstore point of service
oracletransportation management
oracletuxedo system and applications monitor
oraclewebcenter sites
oracleworkload manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD