HIGH · 8.1

CVE-2017-12617

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the De...

Vulnerability Description

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ApacheTomcat>= 7.0.0, < 7.0.82
CanonicalUbuntu Linux12.04
OracleAgile Plm9.3.3
OracleCommunications Instant Messaging Server10.0.1
OracleEndeca Information Discovery Integrator3.1.0
OracleEnterprise Manager For Mysql Database12.1.0.4.0
OracleFinancial Services Analytical Applications Infrastructure>= 7.3.3.0.0, <= 7.3.5.3.0
OracleFmw Platform12.2.1.2.0
OracleHealth Sciences Empirica Inspections1.0.1.1
OracleHospitality Guest Access4.2.0
OracleInstantis Enterprisetrack17.1
OracleManagement Pack11.2.1.0.13
OracleMicros Lucas2.9.5
OracleMicros Retail Xbri Loss Prevention10.0.1
OracleMysql Enterprise Monitor<= 3.3.6.3293
OracleRetail Advanced Inventory Planning13.2
OracleRetail Back Office14.0.4
OracleRetail Central Office14.0.4
OracleRetail Convenience And Fuel Pos Software2.1.132
OracleRetail Eftlink1.1.124

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-12617?

CVE-2017-12617 is a vulnerability with a CVSS score of 8.1 (HIGH). When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the De...

How severe is CVE-2017-12617?

CVE-2017-12617 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-12617?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat, Canonical Ubuntu Linux, Oracle Agile Plm, Oracle Communications Instant Messaging Server, Oracle Endeca Information Discovery Integrator.