CVE-2017-12617 KEV EXPLOIT
8.1
HIGH · CVSS 3.1 · EPSS 100% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-15.
Description
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Scoring
| CVSS | 8.1 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.97% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | yes — remediate by 2022-04-15 |
| Public exploit | yes |
| Published | 2017-10-04 |
| Last modified | 2026-08-25 |
CISA KEV
| Name | Apache Tomcat Remote Code Execution Vulnerability |
|---|---|
| Added | 2022-03-25 |
| Due | 2022-04-15 |
| Vendor / product | Apache / Tomcat |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| apache | tomcat |
| canonical | ubuntu linux |
| debian | debian linux |
| netapp | active iq unified manager |
| netapp | oncommand balance |
| netapp | oncommand insight |
| netapp | oncommand shift |
| netapp | oncommand workflow automation |
| netapp | snapcenter |
| oracle | agile product lifecycle management |
| oracle | communications instant messaging server |
| oracle | endeca information discovery integrator |
| oracle | enterprise manager for mysql database |
| oracle | financial services analytical applications infrastructure |
| oracle | fmw platform |
| oracle | health sciences empirica inspections |
| oracle | hospitality guest access |
| oracle | instantis enterprisetrack |
| oracle | management pack |
| oracle | micros lucas |
| oracle | micros retail xbri loss prevention |
| oracle | mysql enterprise monitor |
| oracle | retail advanced inventory planning |
| oracle | retail back office |
| oracle | retail central office |
| oracle | retail convenience and fuel pos software |
| oracle | retail eftlink |
| oracle | retail insights |
| oracle | retail invoice matching |
| oracle | retail order broker |
| oracle | retail order management system |
| oracle | retail point-of-service |
| oracle | retail price management |
| oracle | retail returns management |
| oracle | retail store inventory management |
| oracle | retail xstore point of service |
| oracle | transportation management |
| oracle | tuxedo system and applications monitor |
| oracle | webcenter sites |
| oracle | workload manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Tomcat - Remote Code Execution via JSP Upload Bypass (Metasploit) | 2017-10-17 |
| exploit-db | Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (2) | 2017-10-09 |
References
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.securityfocus.com/bid/100954
- http://www.securitytracker.com/id/1039552
- https://access.redhat.com/errata/RHSA-2017:3080
- https://access.redhat.com/errata/RHSA-2017:3081
- https://access.redhat.com/errata/RHSA-2017:3113
- https://access.redhat.com/errata/RHSA-2017:3114
- https://access.redhat.com/errata/RHSA-2018:0268
- https://access.redhat.com/errata/RHSA-2018:0269
- https://access.redhat.com/errata/RHSA-2018:0270
- https://access.redhat.com/errata/RHSA-2018:0271
- https://access.redhat.com/errata/RHSA-2018:0275
- https://access.redhat.com/errata/RHSA-2018:0465
- https://access.redhat.com/errata/RHSA-2018:0466
- https://access.redhat.com/errata/RHSA-2018:2939
- https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
→ the Explorer · watch your stack · NVD