CVE-2017-12617

Exp

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Published: 2017-10-03 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2017-12617 is rated Critical Active Threat (97.4/100): CVSS High severity, with high exploitation likelihood (EPSS 99.99%, 100th percentile). Core evidence: CISA KEV confirms active exploitation (added 2022-03-25) affecting Apache / Tomcat. a weakness (CWE-434) Unauthenticated remote administrative access may be possible. EPSS rose +5.63% over the last day, indicating growing attacker interest. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

CISA KEV Record for CVE-2017-12617

Name: Apache Tomcat Remote Code Execution Vulnerability · CISA KEV detail

Exploit added: 2022-03-25

Action due: 2022-04-15

Required action: Apply updates per vendor instructions.

Public exploit references (Exploit-DB) for CVE-2017-12617

EDB-ID Source Kind Published Link
43008 exploit_db edb 2017-10-17 Exploit-DB ↗
42966 exploit_db edb 2017-10-09 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2017-12617

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 94.36% 99.99% +5.63%
2 2026-04-03 94.32% 94.36% +0.04%
3 2026-03-28 94.32%

Full EPSS history (9 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2017-12617

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
8.1 3.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
2.2 5.9 [email protected]
8.1 3.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
2.2 5.9 134c704f-9b21-4f2e-91b3-4a467353bcc0
6.8 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
8.6 6.4 [email protected]

Weakness enumeration for CVE-2017-12617

GitHub Security Advisory for CVE-2017-12617

GHSA-xjgh-84hx-56c5 · Severity: high · Ecosystem: maven — Unrestricted Upload of File with Dangerous Type Apache Tomcat

OS Trackers for CVE-2017-12617

vendor priority summary link
redhat high https://access.redhat.com/security/cve/CVE-2017-12617
suse medium CVE-2017-12617 severity moderate: SUSE including 347 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 552 product×package rows across 40 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (40 product lines)): Known Affected 231, Fixed 203, Known Not Affected 118. https://www.suse.com/security/cve/CVE-2017-12617/
ubuntu high CVE-2017-12617 high priority: Ubuntu including 3 source packages (tomcat7, tomcat8, tomcat8.0), 57 status rows across 20 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, precise, trusty, upstream, xenial, zesty): DNE 42, released 7, ignored 6, not-affected 2. https://ubuntu.com/security/CVE-2017-12617

Affected software / configurations for CVE-2017-12617

Vendor Product Version Raw CPE
apache tomcat >= 7.0.0, < 7.0.82 cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
apache tomcat >= 8.0, < 8.0.47 cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
apache tomcat >= 8.5.0, < 8.5.23 cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
apache tomcat >= 9.0.0, < 9.0.1 cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
canonical ubuntu_linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
canonical ubuntu_linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
canonical ubuntu_linux 17.10 cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
canonical ubuntu_linux 18.04 cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*
oracle agile_plm 9.3.3 cpe:2.3:a:oracle:agile_plm:9.3.3:*:*:*:*:*:*:*
oracle agile_plm 9.3.4 cpe:2.3:a:oracle:agile_plm:9.3.4:*:*:*:*:*:*:*
oracle agile_plm 9.3.5 cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*
oracle agile_plm 9.3.6 cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
oracle communications_instant_messaging_server 10.0.1 cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1:*:*:*:*:*:*:*
oracle endeca_information_discovery_integrator 3.1.0 cpe:2.3:a:oracle:endeca_information_discovery_integrator:3.1.0:*:*:*:*:*:*:*
oracle endeca_information_discovery_integrator 3.2.0 cpe:2.3:a:oracle:endeca_information_discovery_integrator:3.2.0:*:*:*:*:*:*:*
oracle enterprise_manager_for_mysql_database 12.1.0.4.0 cpe:2.3:a:oracle:enterprise_manager_for_mysql_database:12.1.0.4.0:*:*:*:*:*:*:*
oracle financial_services_analytical_applications_infrastructure >= 7.3.3.0.0, <= 7.3.5.3.0 cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*
oracle financial_services_analytical_applications_infrastructure >= 8.0.0.0.0, <= 8.0.9.0.0 cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*
oracle fmw_platform 12.2.1.2.0 cpe:2.3:a:oracle:fmw_platform:12.2.1.2.0:*:*:*:*:*:*:*
oracle fmw_platform 12.2.1.3.0 cpe:2.3:a:oracle:fmw_platform:12.2.1.3.0:*:*:*:*:*:*:*
oracle health_sciences_empirica_inspections 1.0.1.1 cpe:2.3:a:oracle:health_sciences_empirica_inspections:1.0.1.1:*:*:*:*:*:*:*
oracle hospitality_guest_access 4.2.0 cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*
oracle hospitality_guest_access 4.2.1 cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*
oracle instantis_enterprisetrack 17.1 cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*
oracle instantis_enterprisetrack 17.2 cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*
oracle management_pack 11.2.1.0.13 cpe:2.3:a:oracle:management_pack:11.2.1.0.13:*:*:*:*:goldengate:*:*
oracle micros_lucas 2.9.5 cpe:2.3:a:oracle:micros_lucas:2.9.5:*:*:*:*:*:*:*
oracle micros_retail_xbri_loss_prevention 10.0.1 cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.0.1:*:*:*:*:*:*:*
oracle micros_retail_xbri_loss_prevention 10.5.0 cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.5.0:*:*:*:*:*:*:*
oracle micros_retail_xbri_loss_prevention 10.6.0 cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.6.0:*:*:*:*:*:*:*
oracle micros_retail_xbri_loss_prevention 10.7.0 cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.7.0:*:*:*:*:*:*:*
oracle micros_retail_xbri_loss_prevention 10.8.0 cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.8.0:*:*:*:*:*:*:*
oracle micros_retail_xbri_loss_prevention 10.8.1 cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.8.1:*:*:*:*:*:*:*
oracle mysql_enterprise_monitor <= 3.3.6.3293 cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
oracle mysql_enterprise_monitor >= 3.4.0, <= 3.4.4.4226 cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
oracle mysql_enterprise_monitor >= 4.0.0, <= 4.0.0.5135 cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
oracle retail_advanced_inventory_planning 13.2 cpe:2.3:a:oracle:retail_advanced_inventory_planning:13.2:*:*:*:*:*:*:*
oracle retail_advanced_inventory_planning 13.4 cpe:2.3:a:oracle:retail_advanced_inventory_planning:13.4:*:*:*:*:*:*:*
oracle retail_advanced_inventory_planning 14.1 cpe:2.3:a:oracle:retail_advanced_inventory_planning:14.1:*:*:*:*:*:*:*
oracle retail_advanced_inventory_planning 15.0 cpe:2.3:a:oracle:retail_advanced_inventory_planning:15.0:*:*:*:*:*:*:*
oracle retail_back_office 14.0.4 cpe:2.3:a:oracle:retail_back_office:14.0.4:*:*:*:*:*:*:*
oracle retail_back_office 14.1.3 cpe:2.3:a:oracle:retail_back_office:14.1.3:*:*:*:*:*:*:*
oracle retail_central_office 14.0.4 cpe:2.3:a:oracle:retail_central_office:14.0.4:*:*:*:*:*:*:*
oracle retail_central_office 14.1.3 cpe:2.3:a:oracle:retail_central_office:14.1.3:*:*:*:*:*:*:*
oracle retail_convenience_and_fuel_pos_software 2.1.132 cpe:2.3:a:oracle:retail_convenience_and_fuel_pos_software:2.1.132:*:*:*:*:*:*:*
oracle retail_eftlink 1.1.124 cpe:2.3:a:oracle:retail_eftlink:1.1.124:*:*:*:*:*:*:*
oracle retail_eftlink 15.0.1 cpe:2.3:a:oracle:retail_eftlink:15.0.1:*:*:*:*:*:*:*
oracle retail_eftlink 16.0.2 cpe:2.3:a:oracle:retail_eftlink:16.0.2:*:*:*:*:*:*:*
oracle retail_insights 14.0 cpe:2.3:a:oracle:retail_insights:14.0:*:*:*:*:*:*:*
oracle retail_insights 14.1 cpe:2.3:a:oracle:retail_insights:14.1:*:*:*:*:*:*:*
oracle retail_insights 15.0 cpe:2.3:a:oracle:retail_insights:15.0:*:*:*:*:*:*:*
oracle retail_insights 16.0 cpe:2.3:a:oracle:retail_insights:16.0:*:*:*:*:*:*:*
oracle retail_invoice_matching 12.0 cpe:2.3:a:oracle:retail_invoice_matching:12.0:*:*:*:*:*:*:*
oracle retail_invoice_matching 13.0 cpe:2.3:a:oracle:retail_invoice_matching:13.0:*:*:*:*:*:*:*
oracle retail_invoice_matching 13.1 cpe:2.3:a:oracle:retail_invoice_matching:13.1:*:*:*:*:*:*:*
oracle retail_invoice_matching 13.2 cpe:2.3:a:oracle:retail_invoice_matching:13.2:*:*:*:*:*:*:*
oracle retail_invoice_matching 14.0 cpe:2.3:a:oracle:retail_invoice_matching:14.0:*:*:*:*:*:*:*
oracle retail_invoice_matching 14.1 cpe:2.3:a:oracle:retail_invoice_matching:14.1:*:*:*:*:*:*:*
oracle retail_invoice_matching 15.0 cpe:2.3:a:oracle:retail_invoice_matching:15.0:*:*:*:*:*:*:*
oracle retail_invoice_matching 16.0 cpe:2.3:a:oracle:retail_invoice_matching:16.0:*:*:*:*:*:*:*
oracle retail_order_broker 5.0 cpe:2.3:a:oracle:retail_order_broker:5.0:*:*:*:*:*:*:*
oracle retail_order_broker 5.1 cpe:2.3:a:oracle:retail_order_broker:5.1:*:*:*:*:*:*:*
oracle retail_order_broker 5.2 cpe:2.3:a:oracle:retail_order_broker:5.2:*:*:*:*:*:*:*
oracle retail_order_broker 15.0 cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:*
oracle retail_order_broker 16.0 cpe:2.3:a:oracle:retail_order_broker:16.0:*:*:*:*:*:*:*
oracle retail_order_management_system 4.0 cpe:2.3:a:oracle:retail_order_management_system:4.0:*:*:*:*:*:*:*
oracle retail_order_management_system 4.5 cpe:2.3:a:oracle:retail_order_management_system:4.5:*:*:*:*:*:*:*
oracle retail_order_management_system 4.7 cpe:2.3:a:oracle:retail_order_management_system:4.7:*:*:*:*:*:*:*
oracle retail_order_management_system 5.0 cpe:2.3:a:oracle:retail_order_management_system:5.0:*:*:*:*:*:*:*
oracle retail_point-of-service 14.0.4 cpe:2.3:a:oracle:retail_point-of-service:14.0.4:*:*:*:*:*:*:*
oracle retail_point-of-service 14.1.3 cpe:2.3:a:oracle:retail_point-of-service:14.1.3:*:*:*:*:*:*:*
oracle retail_price_management 12.0 cpe:2.3:a:oracle:retail_price_management:12.0:*:*:*:*:*:*:*
oracle retail_price_management 13.0 cpe:2.3:a:oracle:retail_price_management:13.0:*:*:*:*:*:*:*
oracle retail_price_management 13.1 cpe:2.3:a:oracle:retail_price_management:13.1:*:*:*:*:*:*:*
oracle retail_price_management 13.2 cpe:2.3:a:oracle:retail_price_management:13.2:*:*:*:*:*:*:*
oracle retail_price_management 14.0 cpe:2.3:a:oracle:retail_price_management:14.0:*:*:*:*:*:*:*
oracle retail_price_management 14.1 cpe:2.3:a:oracle:retail_price_management:14.1:*:*:*:*:*:*:*
oracle retail_price_management 15.0 cpe:2.3:a:oracle:retail_price_management:15.0:*:*:*:*:*:*:*
oracle retail_price_management 16.0 cpe:2.3:a:oracle:retail_price_management:16.0:*:*:*:*:*:*:*
oracle retail_returns_management 2.3.8 cpe:2.3:a:oracle:retail_returns_management:2.3.8:*:*:*:*:*:*:*

References for CVE-2017-12617

URL Tags
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html Patch Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html Patch Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html Patch Third Party Advisory
http://www.securityfocus.com/bid/100954 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1039552 Broken Link Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2017:3080 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3081 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3113 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3114 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0268 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0269 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0270 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0271 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0275 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0465 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0466 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2939 Third Party Advisory
https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/3fd341a604c4e9eab39e7eaabbbac39c30101a022acc11dd09d7ebcb%40%3Cannounce.tomcat.apache.org%3E Issue Tracking Mailing List
https://lists.apache.org/thread.html/5c0e00fd31efc11e147bf99d0f03c00a734447d3b131ab0818644cdb%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/eb6efa8d59c45a7a9eff94c4b925467d3b3fec8ba7697f3daa314b04%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E Mailing List Patch
https://lists.debian.org/debian-lts-announce/2017/11/msg00009.html Mailing List Third Party Advisory
https://security.netapp.com/advisory/ntap-20171018-0002/ Third Party Advisory
https://security.netapp.com/advisory/ntap-20180117-0002/ Third Party Advisory
https://support.f5.com/csp/article/K53173544 Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03812en_us Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03828en_us Third Party Advisory
https://usn.ubuntu.com/3665-1/ Third Party Advisory
https://www.exploit-db.com/exploits/42966/ Exploit Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/43008/ Exploit Third Party Advisory VDB Entry
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html Patch Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12617 US Government Resource
cvelogic Threat Intelligence