Back to Vulnerability Directory
HIGHFixed upstream

CVE-2017-12617

Apache Tomcat: JSP upload and execution via HTTP PUT

Technology

Apache Tomcat

CVSS Score

8.1 / 10.0

Affected Versions

9.0.0.M1 to 9.0.0; 8.5.0 to 8.5.22; 8.0.0.RC1 to 8.0.46; 7.0.0 to 7.0.81

Upstream Fix

9.0.1; 8.5.23; 8.0.47; 7.0.82

Published

October 4, 2017

OSSeva Coverage

Fixed upstream

Description

With HTTP PUT enabled on the default servlet (readonly set to false), a crafted request could upload a JSP file that the server would then execute. Fixed in 9.0.1, 8.5.23, 8.0.47 and 7.0.82. CISA added it to its Known Exploited Vulnerabilities catalog on 25 March 2022.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 9.0.0.M1 to 9.0.0; 8.5.0 to 8.5.22; 8.0.0.RC1 to 8.0.46; 7.0.0 to 7.0.81, you need this patch. Book a discovery call to get covered.