ZeroHour

CVE-2017-12617

KEV

Apache Tomcat Remote Code Execution Vulnerability

CVSS 3.1
8.1 high
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2017-12617 is a file-upload vulnerability (CWE-434) in Apache Tomcat in which a specially crafted request can upload a JSP file to the server, and any code in that file is executed when the file is later requested, enabling remote code execution. Any organization running an affected version of Apache Tomcat is exposed. Because it allows arbitrary code execution on the web server, it can lead to full server compromise, and it is listed in CISA's Known Exploited Vulnerabilities catalog with a maximal 100% EPSS probability of exploitation within 30 days.

What to do: Apply updates to Apache Tomcat per vendor instructions, which is the required action for this CISA KEV-listed vulnerability. Prioritize patching internet-facing Tomcat instances given the very high likelihood of exploitation, and review patched servers for unexpected or recently created JSP files that could indicate prior exploitation.

Description

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CISA Known Exploited Vulnerability
Affected
Apache Tomcat
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apachecanonicaloracledebiannetappredhat
Products
tomcat, ubuntu linux, agile product lifecycle management, communications instant messaging server, endeca information discovery integrator, enterprise manager for mysql database, financial services analytical applications infrastructure, fmw platform, health sciences empirica inspections, hospitality guest access, instantis enterprisetrack, management pack
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news