CVE-2017-12617

HIGHCVSS 8.1/10Actively ExploitedEPSS 99.99%

Last modified

CVE-2017-12617 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.99% chance of exploitation in the next 30 days.

Description

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Metrics

CVSS 3.1
8.1/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
99.99%

100.0th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Weakness Enumeration

Affected Software

VendorProductVersions
ApacheTomcat>= 7.0.0, < 7.0.82
ApacheTomcat>= 8.0, < 8.0.47
ApacheTomcat>= 8.5.0, < 8.5.23
ApacheTomcat>= 9.0.0, < 9.0.1
CanonicalUbuntu Linux12.04
CanonicalUbuntu Linux16.04
CanonicalUbuntu Linux17.10
CanonicalUbuntu Linux18.04
OracleAgile Plm9.3.3
OracleAgile Plm9.3.4
OracleAgile Plm9.3.5
OracleAgile Plm9.3.6
OracleCommunications Instant Messaging Server10.0.1
OracleEndeca Information Discovery Integrator3.1.0
OracleEndeca Information Discovery Integrator3.2.0
OracleEnterprise Manager For Mysql Database12.1.0.4.0
OracleFinancial Services Analytical Applications Infrastructure>= 7.3.3.0.0, <= 7.3.5.3.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.0.0.0, <= 8.0.9.0.0
OracleFmw Platform12.2.1.2.0
OracleFmw Platform12.2.1.3.0
OracleHealth Sciences Empirica Inspections1.0.1.1
OracleHospitality Guest Access4.2.0
OracleHospitality Guest Access4.2.1
OracleInstantis Enterprisetrack17.1
OracleInstantis Enterprisetrack17.2
OracleManagement Pack11.2.1.0.13
OracleMicros Lucas2.9.5
OracleMicros Retail Xbri Loss Prevention10.0.1
OracleMicros Retail Xbri Loss Prevention10.5.0
OracleMicros Retail Xbri Loss Prevention10.6.0
OracleMicros Retail Xbri Loss Prevention10.7.0
OracleMicros Retail Xbri Loss Prevention10.8.0
OracleMicros Retail Xbri Loss Prevention10.8.1
OracleMysql Enterprise Monitor<= 3.3.6.3293
OracleMysql Enterprise Monitor>= 3.4.0, <= 3.4.4.4226
OracleMysql Enterprise Monitor>= 4.0.0, <= 4.0.0.5135
OracleRetail Advanced Inventory Planning13.2
OracleRetail Advanced Inventory Planning13.4
OracleRetail Advanced Inventory Planning14.1
OracleRetail Advanced Inventory Planning15.0
OracleRetail Back Office14.0.4
OracleRetail Back Office14.1.3
OracleRetail Central Office14.0.4
OracleRetail Central Office14.1.3
OracleRetail Convenience And Fuel Pos Software2.1.132
OracleRetail Eftlink1.1.124
OracleRetail Eftlink15.0.1
OracleRetail Eftlink16.0.2
OracleRetail Insights14.0
OracleRetail Insights14.1

Showing 50 of 157 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2017-12617?
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
How severe is CVE-2017-12617?
CVE-2017-12617 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 99.99% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2017-12617?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-12617?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST