Improper input validation in Apache Tomcat - CVE-2017-12617
Published: October 4, 2017 / Updated: March 25, 2022
Vulnerability identifier: #VU8669
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12617
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists due to insufficient validation of user-supplied input when running with HTTP PUTs enabled. A remote attacker can send a specially crafted request to upload a JSP file to the server and execute arbitrary code on the system.
Successful exploitation of the vulnerability may result in full system compromise.
The weakness exists due to insufficient validation of user-supplied input when running with HTTP PUTs enabled. A remote attacker can send a specially crafted request to upload a JSP file to the server and execute arbitrary code on the system.
Successful exploitation of the vulnerability may result in full system compromise.
Affected software
Apache Tomcat
JBoss Enterprise Web Server
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Fedora
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux
Ubuntu
Opensuse
Dell Support Assist Enterprise
Storage Copy Data Management
EMC Cloud Tiering Appliance
tomcat7 (Ubuntu package)
libtomcat7-java (Ubuntu package)
Tomcat
tomcat6-admin-webapps
tomcat6-webapps
tomcat6-servlet-2_5-api
tomcat6-lib
tomcat6-jsp-2_1-api
tomcat6-javadoc
tomcat6-docs-webapp
tomcat6
tomcat
JBoss Enterprise Web Server
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Fedora
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux
Ubuntu
Opensuse
Dell Support Assist Enterprise
Storage Copy Data Management
EMC Cloud Tiering Appliance
tomcat7 (Ubuntu package)
libtomcat7-java (Ubuntu package)
Tomcat
tomcat6-admin-webapps
tomcat6-webapps
tomcat6-servlet-2_5-api
tomcat6-lib
tomcat6-jsp-2_1-api
tomcat6-javadoc
tomcat6-docs-webapp
tomcat6
tomcat
How to mitigate CVE-2017-12617
The vulnerability is addressed in the following versions: 7.0.82, 8.0.47, 8.5.23 and 9.0.1.
Dell Support Assist Enterprise - update to 4.00.06.00
tomcat7 (Ubuntu package) - update to Ubuntu Pro
libtomcat7-java (Ubuntu package) - update to Ubuntu Pro
Tomcat - update to D.9.0.87.01
Storage Copy Data Management - update to 2.2.26.0
tomcat6-admin-webapps - update to 6.0.53-0.57.19.1
tomcat6-webapps - update to 6.0.53-0.57.19.1
tomcat6-servlet-2_5-api - update to 6.0.53-0.57.19.1
tomcat6-lib - update to 6.0.53-0.57.19.1
tomcat6-jsp-2_1-api - update to 6.0.53-0.57.19.1
tomcat6-javadoc - update to 6.0.53-0.57.19.1
tomcat6-docs-webapp - update to 6.0.53-0.57.19.1
tomcat6 - update to 6.0.53-0.57.19.1
tomcat - addressed in versions 7.0.82-1.el6, 8.0.47-1.fc25, 8.0.47-1.fc26, 8.0.47-1.fc27
EMC Cloud Tiering Appliance - addressed in versions 13.0.0.2.29, 13.1.0.2.20
tomcat7 (Ubuntu package) - update to Ubuntu Pro
libtomcat7-java (Ubuntu package) - update to Ubuntu Pro
Tomcat - update to D.9.0.87.01
Storage Copy Data Management - update to 2.2.26.0
tomcat6-admin-webapps - update to 6.0.53-0.57.19.1
tomcat6-webapps - update to 6.0.53-0.57.19.1
tomcat6-servlet-2_5-api - update to 6.0.53-0.57.19.1
tomcat6-lib - update to 6.0.53-0.57.19.1
tomcat6-jsp-2_1-api - update to 6.0.53-0.57.19.1
tomcat6-javadoc - update to 6.0.53-0.57.19.1
tomcat6-docs-webapp - update to 6.0.53-0.57.19.1
tomcat6 - update to 6.0.53-0.57.19.1
tomcat - addressed in versions 7.0.82-1.el6, 8.0.47-1.fc25, 8.0.47-1.fc26, 8.0.47-1.fc27
EMC Cloud Tiering Appliance - addressed in versions 13.0.0.2.29, 13.1.0.2.20
Links to Public Exploits and PoC-codes
- Exploit #2286 - Exploits (Containing Self Made Perl Reproducers / PoC Codes) (April 7, 2020)
- Exploit #2205 - cve5scan (5 CVE scan and exploit) (March 18, 2020)
- Exploit #1971 - CVE-2017-12617 (Proof of Concept - RCE Exploitation : Web Shell on Apache Tomcat - Ensimag January 2018) (March 18, 2020)
- Exploit #1996 - Alien-Framework (Alien-Framework, it is a framework with many CVE exploits and tools to use in pen-testing.) (March 18, 2020)
- Exploit #1339 - Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (2) (March 18, 2020)
- Exploit #1340 - Tomcat - Remote Code Execution via JSP Upload Bypass (Metasploit) (March 18, 2020)
- Exploit #1752 - Tomcat RCE via JSP Upload Bypass (March 18, 2020)
External References
Related Security Bulletins
- Remote code execution in Apache Tomcat
- Amazon Linux AMI update for tomcat8, tomcat80, tomcat7
- openSUSE update for tomcat
- SUSE Linux update for tomcat
- Red Hat update for jboss
- Red Hat update for jboss
- Red Hat update for jboss
- Red Hat update for jboss
- SUSE Linux update for tomcat
- SUSE Linux update for tomcat
- Red Hat update for Red Hat JBoss Web Server
- Red Hat update for tomcat
- Red Hat update for tomcat6
- SUSE update for tomcat6
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance
- Multiple vulnerabilities in Dell Support Assist Enterprise
- HP-UX update for Tomcat
- Ubuntu update for tomcat7
- Fedora 26 update for tomcat
- Fedora 25 update for tomcat
- Fedora 27 update for tomcat
- Fedora EPEL 6 update for tomcat
- Multiple vulnerabilities in IBM Storage Copy Data Management