imPC@ndo IT

Tracker / CVE-2017-12617

CVE-2017-12617

Exploited High 8.1

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Affected products and versions

apache tomcat · 7.0.0 → 7.0.82
apache tomcat · 8.0 → 8.0.47
apache tomcat · 8.5.0 → 8.5.23
apache tomcat · 9.0.0 → 9.0.1
canonical ubuntu_linux
debian debian_linux
netapp active_iq_unified_manager · 7.3 → …
netapp active_iq_unified_manager · 9.5 → …
netapp element
netapp oncommand_balance
netapp oncommand_insight
netapp oncommand_shift
netapp oncommand_workflow_automation
netapp snapcenter
oracle agile_plm
oracle communications_instant_messaging_server
oracle endeca_information_discovery_integrator
oracle enterprise_manager_for_mysql_database
oracle financial_services_analytical_applications_infrastructure · 7.3.3.0.0 → 7.3.5.3.0
oracle financial_services_analytical_applications_infrastructure · 8.0.0.0.0 → 8.0.9.0.0
oracle fmw_platform
oracle health_sciences_empirica_inspections
oracle hospitality_guest_access
oracle instantis_enterprisetrack
oracle management_pack
oracle micros_lucas
oracle micros_retail_xbri_loss_prevention
oracle mysql_enterprise_monitor · … → 3.3.6.3293
oracle mysql_enterprise_monitor · 3.4.0 → 3.4.4.4226
oracle mysql_enterprise_monitor · 4.0.0 → 4.0.0.5135
oracle retail_advanced_inventory_planning
oracle retail_back_office
oracle retail_central_office
oracle retail_convenience_and_fuel_pos_software
oracle retail_eftlink
oracle retail_insights
oracle retail_invoice_matching
oracle retail_order_broker
oracle retail_order_management_system
oracle retail_point-of-service
oracle retail_price_management
oracle retail_returns_management
oracle retail_store_inventory_management
oracle retail_xstore_point_of_service
oracle transportation_management
oracle tuxedo_system_and_applications_monitor
oracle webcenter_sites
oracle workload_manager
redhat enterprise_linux_desktop
redhat enterprise_linux_eus
redhat enterprise_linux_eus_compute_node
redhat enterprise_linux_for_ibm_z_systems
redhat enterprise_linux_for_ibm_z_systems_eus
redhat enterprise_linux_for_power_big_endian
redhat enterprise_linux_for_power_big_endian_eus
redhat enterprise_linux_for_power_little_endian
redhat enterprise_linux_for_power_little_endian_eus
redhat enterprise_linux_server
redhat enterprise_linux_server_aus
redhat enterprise_linux_server_tus

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References