Improper input validation in Apache Tomcat - CVE-2017-12617

 

Improper input validation in Apache Tomcat - CVE-2017-12617

Published: October 4, 2017 / Updated: March 25, 2022


Vulnerability identifier: #VU8669
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12617
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to insufficient validation of user-supplied input when running with HTTP PUTs enabled. A remote attacker can send a specially crafted request to upload a JSP file to the server and execute arbitrary code on the system.

Successful exploitation of the vulnerability may result in full system compromise.

Affected software

Apache Tomcat
JBoss Enterprise Web Server
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Fedora
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux
Ubuntu
Opensuse
Dell Support Assist Enterprise
Storage Copy Data Management
EMC Cloud Tiering Appliance
tomcat7 (Ubuntu package)
libtomcat7-java (Ubuntu package)
Tomcat
tomcat6-admin-webapps
tomcat6-webapps
tomcat6-servlet-2_5-api
tomcat6-lib
tomcat6-jsp-2_1-api
tomcat6-javadoc
tomcat6-docs-webapp
tomcat6
tomcat

How to mitigate CVE-2017-12617

The vulnerability is addressed in the following versions: 7.0.82, 8.0.47, 8.5.23 and 9.0.1.

Dell Support Assist Enterprise - update to 4.00.06.00
tomcat7 (Ubuntu package) - update to Ubuntu Pro
libtomcat7-java (Ubuntu package) - update to Ubuntu Pro
Tomcat - update to D.9.0.87.01
Storage Copy Data Management - update to 2.2.26.0
tomcat6-admin-webapps - update to 6.0.53-0.57.19.1
tomcat6-webapps - update to 6.0.53-0.57.19.1
tomcat6-servlet-2_5-api - update to 6.0.53-0.57.19.1
tomcat6-lib - update to 6.0.53-0.57.19.1
tomcat6-jsp-2_1-api - update to 6.0.53-0.57.19.1
tomcat6-javadoc - update to 6.0.53-0.57.19.1
tomcat6-docs-webapp - update to 6.0.53-0.57.19.1
tomcat6 - update to 6.0.53-0.57.19.1
tomcat - addressed in versions 7.0.82-1.el6, 8.0.47-1.fc25, 8.0.47-1.fc26, 8.0.47-1.fc27
EMC Cloud Tiering Appliance - addressed in versions 13.0.0.2.29, 13.1.0.2.20

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins