← All CVEs

CVE-2017-12617

high · 8.1Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-25Remediation due 2022-04-15

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

8.1
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2017-10-04
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

Affected products

VendorProductAffected versions
apachetomcat>= 7.0.0, < 7.0.82
apachetomcat>= 8.0, < 8.0.47
apachetomcat>= 8.5.0, < 8.5.23
apachetomcat>= 9.0.0, < 9.0.1
canonicalubuntu_linux12.04
canonicalubuntu_linux16.04
canonicalubuntu_linux17.10
canonicalubuntu_linux18.04
oracleagile_product_lifecycle_management9.3.3
oracleagile_product_lifecycle_management9.3.4
oracleagile_product_lifecycle_management9.3.5
oracleagile_product_lifecycle_management9.3.6
oraclecommunications_instant_messaging_server10.0.1
oracleendeca_information_discovery_integrator3.1.0
oracleendeca_information_discovery_integrator3.2.0
oracleenterprise_manager_for_mysql_database12.1.0.4.0
oraclefinancial_services_analytical_applications_infrastructure>= 7.3.3.0.0, <= 7.3.5.3.0
oraclefinancial_services_analytical_applications_infrastructure>= 8.0.0.0.0, <= 8.0.9.0.0
oraclefmw_platform12.2.1.2.0
oraclefmw_platform12.2.1.3.0
oraclehealth_sciences_empirica_inspections1.0.1.1
oraclehospitality_guest_access4.2.0
oraclehospitality_guest_access4.2.1
oracleinstantis_enterprisetrack17.1
oracleinstantis_enterprisetrack17.2
oraclemanagement_pack11.2.1.0.13
oraclemicros_lucas2.9.5
oraclemicros_retail_xbri_loss_prevention10.0.1
oraclemicros_retail_xbri_loss_prevention10.5.0
oraclemicros_retail_xbri_loss_prevention10.6.0
oraclemicros_retail_xbri_loss_prevention10.7.0
oraclemicros_retail_xbri_loss_prevention10.8.0
oraclemicros_retail_xbri_loss_prevention10.8.1
oraclemysql_enterprise_monitor<= 3.3.6.3293
oraclemysql_enterprise_monitor>= 3.4.0, <= 3.4.4.4226
oraclemysql_enterprise_monitor>= 4.0.0, <= 4.0.0.5135
oracleretail_advanced_inventory_planning13.2
oracleretail_advanced_inventory_planning13.4
oracleretail_advanced_inventory_planning14.1
oracleretail_advanced_inventory_planning15.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-12617