CVE Feed

    Dashboard / CVE / CVE-2017-12617

    CVE-2017-12617

    When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

    Published:Sep 21, 2017
    Last Modified:Aug 25, 2026
    EPS:Oct 3, 2017
    EPSS Score:0.99988
    CVSS Score:8.1

    CISA Notification

    Description

    When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

    Required Action:

    Apply updates per vendor instructions.

    Notes:

    No extra notes provided.

    Due Date
    Apr 15, 2022
    1610 days ago
    Alert Date
    Mar 25, 2022
    1631 days ago

    Affected Products

    Vendor
    Apache
    Product
    Tomcat
    Vendor
    Canonical
    Product
    Ubuntu Linux
    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Netapp
    Product
    Active Iq Unified Manager
    Vendor
    Netapp
    Product
    Element
    Vendor
    Netapp
    Product
    Oncommand Balance
    Vendor
    Netapp
    Product
    Oncommand Insight
    Vendor
    Netapp
    Product
    Oncommand Shift
    Vendor
    Netapp
    Product
    Oncommand Workflow Automation
    Vendor
    Netapp
    Product
    Snapcenter
    Vendor
    Oracle
    Product
    Agile Product Lifecycle Management
    Vendor
    Oracle
    Product
    Communications Instant Messaging Server
    Vendor
    Oracle
    Product
    Endeca Information Discovery Integrator
    Vendor
    Oracle
    Product
    Enterprise Manager For Mysql Database
    Vendor
    Oracle
    Product
    Financial Services Analytical Applications Infrastructure
    Vendor
    Oracle
    Product
    Fmw Platform
    Vendor
    Oracle
    Product
    Health Sciences Empirica Inspections
    Vendor
    Oracle
    Product
    Hospitality Guest Access
    Vendor
    Oracle
    Product
    Instantis Enterprisetrack
    Vendor
    Oracle
    Product
    Management Pack
    Vendor
    Oracle
    Product
    Micros Lucas
    Vendor
    Oracle
    Product
    Micros Retail Xbri Loss Prevention
    Vendor
    Oracle
    Product
    Mysql Enterprise Monitor
    Vendor
    Oracle
    Product
    Retail Advanced Inventory Planning
    Vendor
    Oracle
    Product
    Retail Back Office
    Vendor
    Oracle
    Product
    Retail Central Office
    Vendor
    Oracle
    Product
    Retail Convenience And Fuel Pos Software
    Vendor
    Oracle
    Product
    Retail Eftlink
    Vendor
    Oracle
    Product
    Retail Insights
    Vendor
    Oracle
    Product
    Retail Invoice Matching
    Vendor
    Oracle
    Product
    Retail Order Broker
    Vendor
    Oracle
    Product
    Retail Order Management System
    Vendor
    Oracle
    Product
    Retail Point-of-service
    Vendor
    Oracle
    Product
    Retail Price Management
    Vendor
    Oracle
    Product
    Retail Returns Management
    Vendor
    Oracle
    Product
    Retail Store Inventory Management
    Vendor
    Oracle
    Product
    Retail Xstore Point Of Service
    Vendor
    Oracle
    Product
    Transportation Management
    Vendor
    Oracle
    Product
    Tuxedo System And Applications Monitor
    Vendor
    Oracle
    Product
    Webcenter Sites
    Vendor
    Oracle
    Product
    Workload Manager
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Enterprise Linux Desktop
    Vendor
    Redhat
    Product
    Enterprise Linux Eus
    Vendor
    Redhat
    Product
    Enterprise Linux Eus Compute Node
    Vendor
    Redhat
    Product
    Enterprise Linux For Ibm Z Systems
    Vendor
    Redhat
    Product
    Enterprise Linux For Ibm Z Systems Eus
    Vendor
    Redhat
    Product
    Enterprise Linux For Power Big Endian
    Vendor
    Redhat
    Product
    Enterprise Linux For Power Big Endian Eus
    Vendor
    Redhat
    Product
    Enterprise Linux For Power Little Endian
    Vendor
    Redhat
    Product
    Enterprise Linux For Power Little Endian Eus
    Vendor
    Redhat
    Product
    Enterprise Linux Server
    Vendor
    Redhat
    Product
    Enterprise Linux Server Aus
    Vendor
    Redhat
    Product
    Enterprise Linux Server Tus
    Vendor
    Redhat
    Product
    Enterprise Linux Workstation
    Vendor
    Redhat
    Product
    Fuse
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform
    Vendor
    Redhat
    Product
    Jboss Enterprise Web Server
    Vendor
    Redhat
    Product
    Jboss Enterprise Web Server Text-only Advisories
    Vendor
    Redhat
    Product
    Jboss Fuse

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High