CVE-2017-12617

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
apacheCNA
---
---
CVEADP
---
---
CISA-ADPADP
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
apachetomcat
7.0.0 ≤
𝑥
< 7.0.82
apachetomcat
8.0 ≤
𝑥
< 8.0.47
apachetomcat
8.5.0 ≤
𝑥
< 8.5.23
apachetomcat
9.0.0 ≤
𝑥
< 9.0.1
canonicalubuntu_linux
12.04
canonicalubuntu_linux
16.04
canonicalubuntu_linux
17.10
canonicalubuntu_linux
18.04
oracleagile_plm
9.3.3
oracleagile_plm
9.3.4
oracleagile_plm
9.3.5
oracleagile_plm
9.3.6
oraclecommunications_instant_messaging_server
10.0.1
oracleendeca_information_discovery_integrator
3.1.0
oracleendeca_information_discovery_integrator
3.2.0
oracleenterprise_manager_for_mysql_database
12.1.0.4.0
oraclefinancial_services_analytical_applications_infrastructure
7.3.3.0.0 ≤
𝑥
≤ 7.3.5.3.0
oraclefinancial_services_analytical_applications_infrastructure
8.0.0.0.0 ≤
𝑥
≤ 8.0.9.0.0
oraclefmw_platform
12.2.1.2.0
oraclefmw_platform
12.2.1.3.0
oraclehealth_sciences_empirica_inspections
1.0.1.1
oraclehospitality_guest_access
4.2.0
oraclehospitality_guest_access
4.2.1
oracleinstantis_enterprisetrack
17.1
oracleinstantis_enterprisetrack
17.2
oraclemanagement_pack
11.2.1.0.13
oraclemicros_lucas
2.9.5
oraclemicros_retail_xbri_loss_prevention
10.0.1
oraclemicros_retail_xbri_loss_prevention
10.5.0
oraclemicros_retail_xbri_loss_prevention
10.6.0
oraclemicros_retail_xbri_loss_prevention
10.7.0
oraclemicros_retail_xbri_loss_prevention
10.8.0
oraclemicros_retail_xbri_loss_prevention
10.8.1
oraclemysql_enterprise_monitor
𝑥
≤ 3.3.6.3293
oraclemysql_enterprise_monitor
3.4.0 ≤
𝑥
≤ 3.4.4.4226
oraclemysql_enterprise_monitor
4.0.0 ≤
𝑥
≤ 4.0.0.5135
oracleretail_advanced_inventory_planning
13.2
oracleretail_advanced_inventory_planning
13.4
oracleretail_advanced_inventory_planning
14.1
oracleretail_advanced_inventory_planning
15.0
oracleretail_back_office
14.0.4
oracleretail_back_office
14.1.3
oracleretail_central_office
14.0.4
oracleretail_central_office
14.1.3
oracleretail_convenience_and_fuel_pos_software
2.1.132
oracleretail_eftlink
1.1.124
oracleretail_eftlink
15.0.1
oracleretail_eftlink
16.0.2
oracleretail_insights
14.0
oracleretail_insights
14.1
oracleretail_insights
15.0
oracleretail_insights
16.0
oracleretail_invoice_matching
12.0
oracleretail_invoice_matching
13.0
oracleretail_invoice_matching
13.1
oracleretail_invoice_matching
13.2
oracleretail_invoice_matching
14.0
oracleretail_invoice_matching
14.1
oracleretail_invoice_matching
15.0
oracleretail_invoice_matching
16.0
oracleretail_order_broker
5.0
oracleretail_order_broker
5.1
oracleretail_order_broker
5.2
oracleretail_order_broker
15.0
oracleretail_order_broker
16.0
oracleretail_order_management_system
4.0
oracleretail_order_management_system
4.5
oracleretail_order_management_system
4.7
oracleretail_order_management_system
5.0
oracleretail_point-of-service
14.0.4
oracleretail_point-of-service
14.1.3
oracleretail_price_management
12.0
oracleretail_price_management
13.0
oracleretail_price_management
13.1
oracleretail_price_management
13.2
oracleretail_price_management
14.0
oracleretail_price_management
14.1
oracleretail_price_management
15.0
oracleretail_price_management
16.0
oracleretail_returns_management
2.3.8
oracleretail_returns_management
2.4.9
oracleretail_returns_management
14.0.4
oracleretail_returns_management
14.1.3
oracleretail_store_inventory_management
12.0.12
oracleretail_store_inventory_management
13.0.7
oracleretail_store_inventory_management
13.1.9
oracleretail_store_inventory_management
13.2.9
oracleretail_store_inventory_management
14.0.4
oracleretail_store_inventory_management
14.1.3
oracleretail_store_inventory_management
15.0.2
oracleretail_store_inventory_management
16.0.1
oracleretail_xstore_point_of_service
6.0.11
oracleretail_xstore_point_of_service
7.0.6
oracleretail_xstore_point_of_service
7.1.6
oracleretail_xstore_point_of_service
15.0.1
oracletransportation_management
6.3.1
oracletransportation_management
6.3.2
oracletransportation_management
6.3.3
oracletransportation_management
6.3.4
oracletransportation_management
6.3.5
oracletransportation_management
6.3.6
oracletransportation_management
6.3.7
oracletuxedo_system_and_applications_monitor
12.1.3.0.0
oraclewebcenter_sites
11.1.1.8.0
oracleworkload_manager
12.2.0.1
debiandebian_linux
7.0
netappactive_iq_unified_manager
7.3 ≤
netappactive_iq_unified_manager
9.5 ≤
netapponcommand_balance
-
netapponcommand_insight
-
netapponcommand_shift
-
netapponcommand_workflow_automation
-
netappsnapcenter
-
netappelement
-
redhatfuse
1.0
redhatjboss_enterprise_application_platform
6.0.0
redhatjboss_enterprise_application_platform
6.4.0
redhatjboss_enterprise_web_server
2.0.0
redhatjboss_enterprise_web_server
3.0.0
redhatjboss_enterprise_web_server_text-only_advisories
-
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_eus
7.4
redhatenterprise_linux_eus
7.5
redhatenterprise_linux_eus
7.6
redhatenterprise_linux_eus
7.7
redhatenterprise_linux_eus_compute_node
7.4
redhatenterprise_linux_eus_compute_node
7.5
redhatenterprise_linux_eus_compute_node
7.6
redhatenterprise_linux_eus_compute_node
7.7
redhatenterprise_linux_for_ibm_z_systems
6.0_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems
7.0_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems_eus
7.4_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems_eus
7.5_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems_eus
7.6_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems_eus
7.7_s390x:_s390x
redhatenterprise_linux_for_power_big_endian
6.0_ppc64:_ppc64
redhatenterprise_linux_for_power_big_endian
7.0_ppc64:_ppc64
redhatenterprise_linux_for_power_big_endian_eus
7.4_ppc64:_ppc64
redhatenterprise_linux_for_power_big_endian_eus
7.5_ppc64:_ppc64
redhatenterprise_linux_for_power_big_endian_eus
7.6_ppc64:_ppc64
redhatenterprise_linux_for_power_big_endian_eus
7.7_ppc64:_ppc64
redhatenterprise_linux_for_power_little_endian
7.0
redhatenterprise_linux_for_power_little_endian_eus
7.4_ppc64le:_ppc64le
redhatenterprise_linux_for_power_little_endian_eus
7.5_ppc64le:_ppc64le
redhatenterprise_linux_for_power_little_endian_eus
7.6_ppc64le:_ppc64le
redhatenterprise_linux_for_power_little_endian_eus
7.7_ppc64le:_ppc64le
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_aus
7.6
redhatenterprise_linux_server_aus
7.7
redhatenterprise_linux_server_tus
7.4
redhatenterprise_linux_server_tus
7.6
redhatenterprise_linux_server_tus
7.7
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tomcat7
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
impish
dne
hirsute
dne
groovy
dne
focal
dne
eoan
dne
disco
dne
cosmic
ignored
bionic
needed
artful
ignored
zesty
ignored
xenial
needed
trusty
Fixed 7.0.52-1ubuntu0.14
released
tomcat8
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
impish
dne
hirsute
dne
groovy
dne
focal
dne
eoan
dne
disco
dne
cosmic
not-affected
bionic
not-affected
artful
Fixed 8.5.21-1ubuntu1.1
released
zesty
ignored
xenial
Fixed 8.0.32-1ubuntu1.6
released
trusty
dne
precise
dne
tomcat8.0
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
impish
dne
hirsute
dne
groovy
dne
focal
dne
eoan
dne
disco
dne
cosmic
dne
bionic
dne
artful
ignored
xenial
dne
trusty
dne
References