CVE-2017-12617

Description

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
94.356

Associated Vulnerability

VulnerabilityOS Platform
Update Tomcat to 9.5.14Windows
Update Tomcat to 9.5.5Windows
Update Tomcat to 9.5.7Windows
Update Tomcat to 9.5.8Windows
Update Tomcat to 9.6.10Windows
Update Tomcat to 9.6.3Windows
Update Tomcat to 9.6.4Windows
Update Tomcat to 9.6.7Windows
Update Tomcat to 9.6.8Windows
Update Tomcat to 2.4.5Windows
Update Tomcat to 3.0.14Windows
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat 9.0.1Windows
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat 8.5.23Windows
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat 7.0.82Windows
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat 8.0.47Windows
Vulnerabilities CVE-2017-12617 are fixed in Apache-tomcat-catalina 9.0.1Windows
Vulnerabilities CVE-2017-12617 are fixed in Apache-tomcat-catalina 8.5.23Windows
Vulnerabilities CVE-2017-12617 are fixed in Apache-tomcat-catalina 8.0.47Windows
Vulnerabilities CVE-2017-12617 are fixed in Apache-tomcat-catalina 7.0.82Windows
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat-embed-core 9.0.1Windows
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat-embed-core 8.5.23Windows
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat-embed-core 8.0.47Windows
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat-embed-core 7.0.82Windows
Servlet and JSP engine (USN-3665-1) tomcat7_7.0.52-1ubuntu0.14_all.debLinux
Servlet and JSP engine (USN-3665-1) tomcat8_8.0.32-1ubuntu1.6_all.debLinux
Servlet and JSP engine (USN-3665-1) tomcat8_8.5.21-1ubuntu1.1_all.debLinux
Servlet and JSP engine (USN-3665-1) libtomcat8-java_8.0.32-1ubuntu1.6_all.debLinux
Servlet and JSP engine (USN-3665-1) libtomcat8-java_8.5.21-1ubuntu1.1_all.debLinux
(RHSA-2017:3081) Important: tomcat security update tomcat-7.0.76-3.el7_4.noarch.rpmLinux
(RHSA-2017:3081) Important: tomcat security update tomcat-admin-webapps-7.0.76-3.el7_4.noarch.rpmLinux
(RHSA-2017:3081) Important: tomcat security update tomcat-docs-webapp-7.0.76-3.el7_4.noarch.rpmLinux
(RHSA-2017:3081) Important: tomcat security update tomcat-javadoc-7.0.76-3.el7_4.noarch.rpmLinux
(RHSA-2017:3081) Important: tomcat security update tomcat-jsvc-7.0.76-3.el7_4.noarch.rpmLinux
(RHSA-2017:3081) Important: tomcat security update tomcat-lib-7.0.76-3.el7_4.noarch.rpmLinux
(RHSA-2017:3081) Important: tomcat security update tomcat-webapps-7.0.76-3.el7_4.noarch.rpmLinux
(RHSA-2017:3080) tomcat6 security update tomcat6-el-2.1-api-6.0.24-111.el6_9.noarch.rpmLinux
(RHSA-2017:3080) tomcat6 security update tomcat6-jsp-2.1-api-6.0.24-111.el6_9.noarch.rpmLinux
(RHSA-2017:3080) tomcat6 security update tomcat6-servlet-2.5-api-6.0.24-111.el6_9.noarch.rpmLinux
Update Tomcat to 9.5.14 (For Linux)Linux
Update Tomcat to 9.5.5 (For Linux)Linux
Update Tomcat to 9.5.7 (For Linux)Linux
Update Tomcat to 9.5.8 (For Linux)Linux
Update Tomcat to 9.6.10 (For Linux)Linux
Update Tomcat to 9.6.3 (For Linux)Linux
Update Tomcat to 9.6.4 (For Linux)Linux
Update Tomcat to 9.6.7 (For Linux)Linux
Update Tomcat to 9.6.8 (For Linux)Linux
Update Tomcat to 2.4.5 (For Linux)Linux
Update Tomcat to 3.0.14 (For Linux)Linux
(CESA-2017:3081) Important: tomcat security update tomcat-7.0.76-3.el7_4.noarch.rpmLinux
(CESA-2017:3081) Important: tomcat security update tomcat-admin-webapps-7.0.76-3.el7_4.noarch.rpmLinux
(CESA-2017:3081) Important: tomcat security update tomcat-docs-webapp-7.0.76-3.el7_4.noarch.rpmLinux
(CESA-2017:3081) Important: tomcat security update tomcat-javadoc-7.0.76-3.el7_4.noarch.rpmLinux
(CESA-2017:3081) Important: tomcat security update tomcat-jsvc-7.0.76-3.el7_4.noarch.rpmLinux
(CESA-2017:3081) Important: tomcat security update tomcat-lib-7.0.76-3.el7_4.noarch.rpmLinux
(CESA-2017:3081) Important: tomcat security update tomcat-webapps-7.0.76-3.el7_4.noarch.rpmLinux
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat for Linux 9.0.1Linux
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat for Linux 8.5.23Linux
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat for Linux 7.0.82Linux
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat for Linux 8.0.47Linux
Vulnerabilities CVE-2017-12617 are fixed in Apache-tomcat-catalina for Linux 9.0.1Linux
Vulnerabilities CVE-2017-12617 are fixed in Apache-tomcat-catalina for Linux 8.5.23Linux
Vulnerabilities CVE-2017-12617 are fixed in Apache-tomcat-catalina for Linux 8.0.47Linux
Vulnerabilities CVE-2017-12617 are fixed in Apache-tomcat-catalina for Linux 7.0.82Linux
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat-embed-core for Linux 9.0.1Linux
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat-embed-core for Linux 8.5.23Linux
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat-embed-core for Linux 8.0.47Linux
Vulnerabilities CVE-2017-12617 are fixed in Apache - tomcat-embed-core for Linux 7.0.82Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234