SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2017-12617

Apache Tomcat Remote Code Execution Vulnerability

KEVHIGH 8.1EPSS 100.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.99% probability · 100th percentile
CISA KEV
Listed 25 March 2022 · due 15 April 2022
Weakness
CWE-434
Affected
apache/tomcat · canonical/ubuntu linux · oracle/agile product lifecycle management · oracle/communications instant messaging server · oracle/endeca information discovery integrator · oracle/enterprise manager for mysql database · oracle/financial services analytical applications infrastructure · oracle/fmw platform · oracle/health sciences empirica inspections · oracle/hospitality guest access · oracle/instantis enterprisetrack · oracle/management pack · oracle/micros lucas · oracle/micros retail xbri loss prevention · oracle/mysql enterprise monitor · oracle/retail advanced inventory planning · oracle/retail back office · oracle/retail central office · oracle/retail convenience and fuel pos software · oracle/retail eftlink · +38 more
Source
security@apache.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2017-12617

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.