Security features in Apache Tomcat - CVE-2017-15706

 

Security features in Apache Tomcat - CVE-2017-15706

Published: April 27, 2018


Vulnerability identifier: #VU12274
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15706
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write arbitrary files on the target system.

The weakness exists due to some scripts may have failed to execute as expected and other scripts may have been executed unexpectedly. A remote attacker can write arbitrary files.

Affected software

Apache Tomcat
Amazon Linux AMI
Fedora
tomcat

How to mitigate CVE-2017-15706

Install update from vendor's website.

tomcat - addressed in versions 7.0.84-1.el6, 8.0.49-1.fc26, 8.0.49-1.fc27

External References

Related Security Bulletins