Junglewise Threat Intelligence

CVE-2017-12617: Unrestricted Upload of File with Dangerous Type Apache Tomcat

CVE-2017-12617 · Severity: critical · CVSS 3 · Exploited in the wild · Published 2022-05-14

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat allows remote code execution when HTTP PUT requests are enabled. An attacker can upload a specially crafted JSP file to the server, which can then be executed by requesting the file.

Affected products

  • Apache Tomcat 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46, 7.0.0 to 7.0.81

Timeline

  • 2022-03-25: disclosed: Publication date of the advisory.
  • exploited: Reported as exploited in the wild.

Related threats