CVE-2017-12617: Apache Tomcat Remote Code Execution Vulnerability
High severity, CVSS 8.1. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 100% chance of exploitation in the next 30 days.
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Affected products
- Apache Tomcat: from 7.0.0, before 7.0.82 (fixed in 7.0.82); from 8.0, before 8.0.47 (fixed in 8.0.47); from 8.5.0, before 8.5.23 (fixed in 8.5.23); from 9.0.0, before 9.0.1 (fixed in 9.0.1)
- Canonical Ubuntu Linux: version 12.04 only; version 16.04 only; version 17.10 only; version 18.04 only
- Debian Debian Linux: version 7.0 only
- Netapp Active Iq Unified Manager: from 7.3; from 9.5
- Netapp Element: affected versions not specified
- Netapp Oncommand Balance: affected versions not specified
- Netapp Oncommand Insight: affected versions not specified
- Netapp Oncommand Shift: affected versions not specified
- Netapp Oncommand Workflow Automation: affected versions not specified
- Netapp Snapcenter: affected versions not specified
- Oracle Agile Product Lifecycle Management: version 9.3.3 only; version 9.3.4 only; version 9.3.5 only; version 9.3.6 only
- Oracle Communications Instant Messaging Server: version 10.0.1 only
- Oracle Endeca Information Discovery Integrator: version 3.1.0 only; version 3.2.0 only
- Oracle Enterprise Manager For MySQL Database: version 12.1.0.4.0 only
- Oracle Financial Services Analytical Applications Infrastructure: from 7.3.3.0.0, up to and including 7.3.5.3.0; from 8.0.0.0.0, up to and including 8.0.9.0.0
- Oracle Fmw Platform: version 12.2.1.2.0 only; version 12.2.1.3.0 only
- Oracle Health Sciences Empirica Inspections: version 1.0.1.1 only
- Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
- Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only
- Oracle Management Pack: version 11.2.1.0.13 only
- Oracle Micros Lucas: version 2.9.5 only
- Oracle Micros Retail Xbri Loss Prevention: version 10.0.1 only; version 10.5.0 only; version 10.6.0 only; version 10.7.0 only; version 10.8.0 only; version 10.8.1 only
- Oracle MySQL Enterprise Monitor: up to and including 3.3.6.3293; from 3.4.0, up to and including 3.4.4.4226; from 4.0.0, up to and including 4.0.0.5135
- Oracle Retail Advanced Inventory Planning: version 13.2 only; version 13.4 only; version 14.1 only; version 15.0 only
- Oracle Retail Back Office: version 14.0.4 only; version 14.1.3 only
- and 33 more
Published 2017-10-04. Last modified 2026-08-25.