CISA KEV · Known exploitedHigh

CVE-2017-12617

Apache Tomcat

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVSS
8.1
EPSS
100.0%
100.0% percentile
CISA KEV
Listed
Published
2017.10.04
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability100.0%
Technical severityCVSS 8.1

Vulnerability overview

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Affected product and versions

Product
Apache Tomcat
Affected versions
9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46, 7.0.0 to 7.0.81, >= 7.0.0 < 7.0.82, >= 8.0 < 8.0.47, >= 8.5.0 < 8.5.23, >= 9.0.0 < 9.0.1, 12.04, 16.04, 17.10, 18.04, 9.3.3, 9.3.4, 9.3.5, 9.3.6, 10.0.1, 3.1.0, 3.2.0, 12.1.0.4.0
Fixed versions
7.0.82, 8.0.47, 8.5.23, 9.0.1

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

Apply updates per vendor instructions.

Due date: 2022.04.15
  1. 1
    Identify

    Confirm that Apache Tomcat and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-434
KEV added
2022.03.25
Ransomware use
미확인