CVE-2017-12617
Last modified
CVE-2017-12617 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.99% chance of exploitation in the next 30 days.
Description
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | >= 7.0.0, < 7.0.82 |
| Apache | Tomcat | >= 8.0, < 8.0.47 |
| Apache | Tomcat | >= 8.5.0, < 8.5.23 |
| Apache | Tomcat | >= 9.0.0, < 9.0.1 |
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 17.10 |
| Canonical | Ubuntu Linux | 18.04 |
| Oracle | Agile Plm | 9.3.3 |
| Oracle | Agile Plm | 9.3.4 |
| Oracle | Agile Plm | 9.3.5 |
| Oracle | Agile Plm | 9.3.6 |
| Oracle | Communications Instant Messaging Server | 10.0.1 |
| Oracle | Endeca Information Discovery Integrator | 3.1.0 |
| Oracle | Endeca Information Discovery Integrator | 3.2.0 |
| Oracle | Enterprise Manager For Mysql Database | 12.1.0.4.0 |
| Oracle | Financial Services Analytical Applications Infrastructure | >= 7.3.3.0.0, <= 7.3.5.3.0 |
| Oracle | Financial Services Analytical Applications Infrastructure | >= 8.0.0.0.0, <= 8.0.9.0.0 |
| Oracle | Fmw Platform | 12.2.1.2.0 |
| Oracle | Fmw Platform | 12.2.1.3.0 |
| Oracle | Health Sciences Empirica Inspections | 1.0.1.1 |
| Oracle | Hospitality Guest Access | 4.2.0 |
| Oracle | Hospitality Guest Access | 4.2.1 |
| Oracle | Instantis Enterprisetrack | 17.1 |
| Oracle | Instantis Enterprisetrack | 17.2 |
| Oracle | Management Pack | 11.2.1.0.13 |
| Oracle | Micros Lucas | 2.9.5 |
| Oracle | Micros Retail Xbri Loss Prevention | 10.0.1 |
| Oracle | Micros Retail Xbri Loss Prevention | 10.5.0 |
| Oracle | Micros Retail Xbri Loss Prevention | 10.6.0 |
| Oracle | Micros Retail Xbri Loss Prevention | 10.7.0 |
| Oracle | Micros Retail Xbri Loss Prevention | 10.8.0 |
| Oracle | Micros Retail Xbri Loss Prevention | 10.8.1 |
| Oracle | Mysql Enterprise Monitor | <= 3.3.6.3293 |
| Oracle | Mysql Enterprise Monitor | >= 3.4.0, <= 3.4.4.4226 |
| Oracle | Mysql Enterprise Monitor | >= 4.0.0, <= 4.0.0.5135 |
| Oracle | Retail Advanced Inventory Planning | 13.2 |
| Oracle | Retail Advanced Inventory Planning | 13.4 |
| Oracle | Retail Advanced Inventory Planning | 14.1 |
| Oracle | Retail Advanced Inventory Planning | 15.0 |
| Oracle | Retail Back Office | 14.0.4 |
| Oracle | Retail Back Office | 14.1.3 |
| Oracle | Retail Central Office | 14.0.4 |
| Oracle | Retail Central Office | 14.1.3 |
| Oracle | Retail Convenience And Fuel Pos Software | 2.1.132 |
| Oracle | Retail Eftlink | 1.1.124 |
| Oracle | Retail Eftlink | 15.0.1 |
| Oracle | Retail Eftlink | 16.0.2 |
| Oracle | Retail Insights | 14.0 |
| Oracle | Retail Insights | 14.1 |
Showing 50 of 157 affected configurations. See NVD for the full list.
References
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/100954Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039552Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:3080Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3081Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3113Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3114Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0268Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0269Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0270Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0271Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0275Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0465Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0466Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2939Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2017/11/msg00009.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20171018-0002/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180117-0002/Third Party Advisory
- https://support.f5.com/csp/article/K53173544Third Party Advisory
- https://usn.ubuntu.com/3665-1/Third Party Advisory
- https://www.exploit-db.com/exploits/42966/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/43008/Exploit, Third Party Advisory, VDB Entry
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/100954Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039552Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:3080Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3081Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3113Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3114Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0268Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0269Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0270Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0271Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0275Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0465Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0466Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2939Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2017/11/msg00009.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20171018-0002/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180117-0002/Third Party Advisory
- https://support.f5.com/csp/article/K53173544Third Party Advisory
- https://usn.ubuntu.com/3665-1/Third Party Advisory
- https://www.exploit-db.com/exploits/42966/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/43008/Exploit, Third Party Advisory, VDB Entry
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12617US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2017-12617?
How severe is CVE-2017-12617?
How do I fix CVE-2017-12617?
Are you affected by CVE-2017-12617?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
