CVE-2017-12617 Details
Description
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
A remote code execution vulnerability has been identified in Apache Tomcat versions 9.0.0.M1 prior to 9.0.0, 8.5.0 prior to 8.5.23, 8.0.0.RC1 prior to 8.0.47, and 7.0.0 prior to 7.0.82. When HTTP PUT requests were enabled, it was possible to upload a JSP file to the server through a specially crafted request. The uploaded JSP file could then be accessed, and any code it contained would be executed by the server.
Users should upgrade to Apache Tomcat 9.0.1 or later, 8.5.23 or later, 8.0.47 or later, or 7.0.82 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Apache Tomcat Remote Code Execution Vulnerability | Mar 25, 2022 | Apr 15, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apache tomcat | >= 7.0.0, < 7.0.82 >= 8.0, < 8.0.47 >= 8.5.0, < 8.5.23 >= 9.0.0, < 9.0.1 |
CPE
Remediation
| |
| canonical ubuntu linux | 12.04 16.04 17.10 18.04 |
CPE
Remediation
| |
| oracle agile product lifecycle management | 9.3.3 9.3.4 9.3.5 9.3.6 |
CPE
Remediation
| |
| oracle communications instant messaging server | 10.0.1 |
CPE
Remediation
| |
| oracle endeca information discovery integrator | 3.1.0 3.2.0 |
CPE
Remediation
| |
| oracle enterprise manager for mysql database | 12.1.0.4.0 |
CPE
Remediation
| |
| oracle financial services analytical applications infrastructure | >= 7.3.3.0.0, <= 7.3.5.3.0 >= 8.0.0.0.0, <= 8.0.9.0.0 |
CPE
Remediation
| |
| oracle fmw platform | 12.2.1.2.0 12.2.1.3.0 |
CPE
Remediation
| |
| oracle health sciences empirica inspections | 1.0.1.1 |
CPE
Remediation
| |
| oracle hospitality guest access | 4.2.0 4.2.1 |
CPE
Remediation
| |
| oracle instantis enterprisetrack | 17.1 17.2 |
CPE
Remediation
| |
| oracle management pack | 11.2.1.0.13 |
CPE
Remediation
| |
| oracle micros lucas | 2.9.5 |
CPE
Remediation
| |
| oracle micros retail xbri loss prevention | 10.0.1 10.5.0 10.6.0 10.7.0 10.8.0 10.8.1 |
CPE
Remediation
| |
| oracle mysql enterprise monitor | <= 3.3.6.3293 >= 3.4.0, <= 3.4.4.4226 >= 4.0.0, <= 4.0.0.5135 |
CPE
Remediation
| |
| oracle retail advanced inventory planning | 13.2 13.4 14.1 15.0 |
CPE
Remediation
| |
| oracle retail back office | 14.0.4 14.1.3 |
CPE
Remediation
| |
| oracle retail central office | 14.0.4 14.1.3 |
CPE
Remediation
| |
| oracle retail convenience and fuel pos software | 2.1.132 |
CPE
Remediation
| |
| oracle retail eftlink | 1.1.124 15.0.1 16.0.2 |
CPE
Remediation
| |
| oracle retail insights | 14.0 14.1 15.0 16.0 |
CPE
Remediation
| |
| oracle retail invoice matching | 12.0 13.0 13.1 13.2 14.0 14.1 15.0 16.0 |
CPE
Remediation
| |
| oracle retail order broker | 5.0 5.1 5.2 15.0 16.0 |
CPE
Remediation
| |
| oracle retail order management system | 4.0 4.5 4.7 5.0 |
CPE
Remediation
| |
| oracle retail point-of-service | 14.0.4 14.1.3 |
CPE
Remediation
| |
| oracle retail price management | 12.0 13.0 13.1 13.2 14.0 14.1 15.0 16.0 |
CPE
Remediation
| |
| oracle retail returns management | 2.3.8 2.4.9 14.0.4 14.1.3 |
CPE
Remediation
| |
| oracle retail store inventory management | 12.0.12 13.0.7 13.1.9 13.2.9 14.0.4 14.1.3 15.0.2 16.0.1 |
CPE
Remediation
| |
| oracle retail xstore point of service | 6.0.11 7.0.6 7.1.6 15.0.1 |
CPE
Remediation
| |
| oracle transportation management | 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 |
CPE
Remediation
| |
| oracle tuxedo system and applications monitor | 12.1.3.0.0 |
CPE
Remediation
| |
| oracle webcenter sites | 11.1.1.8.0 |
CPE
Remediation
| |
| oracle workload manager | 12.2.0.1 |
CPE
Remediation
| |
| debian debian linux | 7.0 |
CPE
Remediation
| |
| netapp active iq unified manager | >= 7.3 >= 9.5 |
CPE
Remediation
| |
| netapp oncommand balance | All versions |
CPE
Remediation
| |
| netapp oncommand insight | All versions |
CPE
Remediation
| |
| netapp oncommand shift | All versions |
CPE
Remediation
| |
| netapp oncommand workflow automation | All versions |
CPE
Remediation
| |
| netapp snapcenter | All versions |
CPE
Remediation
| |
| netapp element | All versions |
CPE
Remediation
| |
| redhat fuse | 1.0 |
CPE
Remediation
| |
| redhat jboss enterprise application platform | 6.0.0 6.4.0 |
CPE
Remediation
| |
| redhat jboss enterprise web server | 2.0.0 3.0.0 |
CPE
Remediation
| |
| redhat jboss enterprise web server text-only advisories | All versions |
CPE
Remediation
| |
| redhat enterprise linux desktop | 6.0 7.0 |
CPE
Remediation
| |
| redhat enterprise linux eus | 7.4 7.5 7.6 7.7 |
CPE
Remediation
| |
| redhat enterprise linux eus compute node | 7.4 7.5 7.6 7.7 |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems | 6.0_s390x 7.0_s390x |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems eus | 7.4_s390x 7.5_s390x 7.6_s390x 7.7_s390x |
CPE
Remediation
| |
| redhat enterprise linux for power big endian | 6.0_ppc64 7.0_ppc64 |
CPE
Remediation
| |
| redhat enterprise linux for power big endian eus | 7.4_ppc64 7.5_ppc64 7.6_ppc64 7.7_ppc64 |
CPE
Remediation
| |
| redhat enterprise linux for power little endian | 7.0 |
CPE
Remediation
| |
| redhat enterprise linux for power little endian eus | 7.4_ppc64le 7.5_ppc64le 7.6_ppc64le 7.7_ppc64le |
CPE
Remediation
| |
| redhat enterprise linux server | 6.0 7.0 |
CPE
Remediation
| |
| redhat enterprise linux server aus | 7.4 7.6 7.7 |
CPE
Remediation
| |
| redhat enterprise linux server tus | 7.4 7.6 7.7 |
CPE
Remediation
| |
| redhat enterprise linux workstation | 6.0 7.0 |
CPE
Remediation
| |
Change History
63 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 25, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 25, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 25, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 25, 2026 | CPE Deprecation Remap | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Feb 6, 2025 | Modified Analysis | [email protected] |
| Feb 4, 2025 | CVE Modified | CISA-ADP |
| Jan 23, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 16, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Feb 13, 2020 | CVE Modified | [email protected] |
| Feb 3, 2020 | CVE Modified | [email protected] |
| Apr 23, 2019 | CVE Modified | [email protected] |
| Apr 15, 2019 | CVE Modified | [email protected] |
| Apr 15, 2019 | CVE Modified | [email protected] |
| Mar 25, 2019 | CVE Modified | [email protected] |
| Mar 25, 2019 | CVE Modified | [email protected] |
| Mar 21, 2019 | CVE Modified | [email protected] |
| Oct 18, 2018 | CVE Modified | [email protected] |
| Jul 19, 2018 | CVE Modified | [email protected] |
| Jun 1, 2018 | CVE Modified | [email protected] |
| May 10, 2018 | CVE Modified | [email protected] |
| Apr 20, 2018 | CVE Modified | [email protected] |
| Mar 9, 2018 | CVE Modified | [email protected] |
| Feb 7, 2018 | CVE Modified | [email protected] |
| Feb 4, 2018 | CVE Modified | [email protected] |
| Jan 18, 2018 | CVE Modified | [email protected] |
| Dec 2, 2017 | CVE Modified | [email protected] |
| Nov 10, 2017 | CVE Modified | [email protected] |
| Oct 23, 2017 | Initial Analysis | [email protected] |
| Oct 20, 2017 | CVE Modified | [email protected] |
| Oct 19, 2017 | CVE Modified | [email protected] |
| Oct 12, 2017 | CVE Modified | [email protected] |
| Oct 5, 2017 | CVE Modified | [email protected] |