Back to Vulnerability Directory
HIGHFixed upstream
CVE-2017-12617
Apache Tomcat: JSP upload and execution via HTTP PUT
Technology
Apache Tomcat
CVSS Score
8.1 / 10.0
Affected Versions
9.0.0.M1 to 9.0.0; 8.5.0 to 8.5.22; 8.0.0.RC1 to 8.0.46; 7.0.0 to 7.0.81
Upstream Fix
9.0.1; 8.5.23; 8.0.47; 7.0.82
Published
October 4, 2017
OSSeva Coverage
Fixed upstream
Description
With HTTP PUT enabled on the default servlet (readonly set to false), a crafted request could upload a JSP file that the server would then execute. Fixed in 9.0.1, 8.5.23, 8.0.47 and 7.0.82. CISA added it to its Known Exploited Vulnerabilities catalog on 25 March 2022.
Is your Apache Tomcat deployment affected?
If you're running 9.0.0.M1 to 9.0.0; 8.5.0 to 8.5.22; 8.0.0.RC1 to 8.0.46; 7.0.0 to 7.0.81, you need this patch. Book a discovery call to get covered.