RaqibCTI
CVE

CVE-2017-12617

P2
Apache Tomcat Remote Code Execution Vulnerability
Apache · Tomcat
Date added (CISA)
2022-03-25
Remediation due
2022-04-15
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Source: NVD ↗ · CISA KEV Catalog ↗