Apache Tomcat CVE-2017-12617 Incomplete Fix Remote Code Execution Vulnerability
BID:100954
Info
Apache Tomcat CVE-2017-12617 Incomplete Fix Remote Code Execution Vulnerability
| Bugtraq ID: | 100954 |
| Class: | Configuration Error |
| CVE: |
CVE-2017-12617 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2017 12:00AM |
| Updated: | Apr 18 2018 07:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Redhat JBoss Web Server (JWS) 3.0 Redhat JBoss EWS 2 Oracle WebCenter Sites 11.1.1 8.0 Oracle Tuxedo System and Applications Monitor 12.1.3.0.0 Oracle Transportation Management 6.3.5 Oracle Transportation Management 6.3.4 Oracle Transportation Management 6.3.3 Oracle Transportation Management 6.3.2 Oracle Transportation Management 6.3.1 Oracle Transportation Management 6.3.7 Oracle Transportation Management 6.3.6 Oracle Retail Order Broker 5.2 Oracle Retail Order Broker 15.0 Oracle MySQL Enterprise Monitor 3.2.1182 Oracle MySQL Enterprise Monitor 3.0.22 Oracle MySQL Enterprise Monitor 3.0.20 Oracle MySQL Enterprise Monitor 3.0.18 Oracle MySQL Enterprise Monitor 3.0.10 Oracle MySQL Enterprise Monitor 3.0.9 Oracle MySQL Enterprise Monitor 3.0.8 Oracle MySQL Enterprise Monitor 3.0 Oracle MySQL Enterprise Monitor 4.0.0.5135 Oracle MySQL Enterprise Monitor 3.4.4.4226 Oracle MySQL Enterprise Monitor 3.4.2.4181 Oracle MySQL Enterprise Monitor 3.4.1 Oracle MySQL Enterprise Monitor 3.3.6.3293 Oracle MySQL Enterprise Monitor 3.3.4.3247 Oracle MySQL Enterprise Monitor 3.3.3.1199 Oracle MySQL Enterprise Monitor 3.3.2.1162 Oracle MySQL Enterprise Monitor 3.3.0.1098 Oracle MySQL Enterprise Monitor 3.2.8.2223 Oracle MySQL Enterprise Monitor 3.2.7.1204 Oracle MySQL Enterprise Monitor 3.2.5.1141 Oracle MySQL Enterprise Monitor 3.2.4.1102 Oracle MySQL Enterprise Monitor 3.2.1.1049 Oracle MySQL Enterprise Monitor 3.1.6.8003 Oracle MySQL Enterprise Monitor 3.1.5.7958 Oracle MySQL Enterprise Monitor 3.1.4.7895 Oracle MySQL Enterprise Monitor 3.1.3.7856 Oracle MySQL Enterprise Monitor 3.1.2 Oracle MySQL Enterprise Monitor 3.0.4 Oracle MySQL Enterprise Monitor 3.0.25 Oracle MySQL Enterprise Monitor 3.0 Oracle MICROS Retail XBRi Loss Prevention 10.8.1 Oracle MICROS Retail XBRi Loss Prevention 10.8 Oracle MICROS Retail XBRi Loss Prevention 10.7 Oracle MICROS Retail XBRi Loss Prevention 10.6 Oracle MICROS Retail XBRi Loss Prevention 10.5 Oracle MICROS Retail XBRi Loss Prevention 10.0.1 Oracle Management Pack for Oracle GoldenGate 11.2.1.0.13 Oracle Instantis EnterpriseTrack 17.2 Oracle Instantis EnterpriseTrack 17.1 Oracle Hospitality Guest Access 4.2.1.0 Oracle Hospitality Guest Access 4.2.0.0 Oracle Health Sciences Empirica Inspections 1.0.1.1 Oracle Financial Services Analytical Applications Infrastructure 8.0.3 Oracle Financial Services Analytical Applications Infrastructure 8.0.2 Oracle Financial Services Analytical Applications Infrastructure 8.0.1 Oracle Financial Services Analytical Applications Infrastructure 8.0 Oracle Financial Services Analytical Applications Infrastructure 7.3.5 Oracle Financial Services Analytical Applications Infrastructure 7.3.4 Oracle Financial Services Analytical Applications Infrastructure 7.3.3 Oracle Financial Services Analytical Applications Infrastructure 7.3.2 Oracle Financial Services Analytical Applications Infrastructure 7.3.1 Oracle Financial Services Analytical Applications Infrastructure 7.3 Oracle Endeca Information Discovery Integrator 3.2 Oracle Endeca Information Discovery Integrator 3.1 Oracle Database 12c Release 2 12.2.0.1 Oracle Agile PLM 9.3.5 Oracle Agile PLM 9.3.3 Oracle Agile PLM 9.3.6 Oracle Agile PLM 9.3.4 Bluecoat X-Series XOS 9.7 Bluecoat X-Series XOS 11.0 Bluecoat X-Series XOS 10.0 Bluecoat IntelligenceCenter Data Collector 3.3 Bluecoat IntelligenceCenter 3.3 Bluecoat Director 6.1 Apache Tomcat 7.0.81 Apache Tomcat 7.0.79 Apache Tomcat 7.0.78 Apache Tomcat 7.0.77 Apache Tomcat 7.0.76 Apache Tomcat 7.0.75 Apache Tomcat 7.0.74 Apache Tomcat 7.0.73 Apache Tomcat 7.0.72 Apache Tomcat 7.0.70 Apache Tomcat 7.0.69 Apache Tomcat 7.0.67 Apache Tomcat 7.0.65 Apache Tomcat 7.0.60 Apache Tomcat 7.0.59 Apache Tomcat 7.0.57 Apache Tomcat 7.0.54 Apache Tomcat 7.0.53 Apache Tomcat 7.0.50 Apache Tomcat 7.0.33 Apache Tomcat 7.0.32 Apache Tomcat 7.0.31 Apache Tomcat 7.0.30 Apache Tomcat 7.0.29 Apache Tomcat 7.0.28 Apache Tomcat 7.0.27 Apache Tomcat 7.0.26 Apache Tomcat 7.0.25 Apache Tomcat 7.0.24 Apache Tomcat 7.0.23 Apache Tomcat 7.0.17 Apache Tomcat 7.0.16 Apache Tomcat 7.0.15 Apache Tomcat 7.0.14 Apache Tomcat 7.0.13 Apache Tomcat 7.0.12 Apache Tomcat 7.0.9 Apache Tomcat 7.0.8 Apache Tomcat 7.0.7 Apache Tomcat 7.0.6 Apache Tomcat 7.0.4 Apache Tomcat 7.0.3 Apache Tomcat 7.0.2 Apache Tomcat 7.0.1 Apache Tomcat 7.0 Apache Tomcat 7.0.68 Apache Tomcat 7.0.55 Apache Tomcat 7.0.5 Apache Tomcat 7.0.49 Apache Tomcat 7.0.48 Apache Tomcat 7.0.47 Apache Tomcat 7.0.46 Apache Tomcat 7.0.45 Apache Tomcat 7.0.44 Apache Tomcat 7.0.43 Apache Tomcat 7.0.42 Apache Tomcat 7.0.41 Apache Tomcat 7.0.40 Apache Tomcat 7.0.39 Apache Tomcat 7.0.38 Apache Tomcat 7.0.37 Apache Tomcat 7.0.36 Apache Tomcat 7.0.35 Apache Tomcat 7.0.34 Apache Tomcat 7.0.22 Apache Tomcat 7.0.21 Apache Tomcat 7.0.20 Apache Tomcat 7.0.19 Apache Tomcat 7.0.18 Apache Tomcat 7.0.11 Apache Tomcat 7.0.10 |
| Not Vulnerable: | |
Discussion
Apache Tomcat CVE-2017-12617 Incomplete Fix Remote Code Execution Vulnerability
Apache Tomcat is prone to a remote code-execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application.
Apache Tomcat 7.0.81 and prior versions are vulnerable.
NOTE: This issue is the result of an incomplete fix for the issue described in BID 100901 (Apache Tomcat CVE-2017-12615 Remote Code Execution Vulnerability).
Apache Tomcat is prone to a remote code-execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application.
Apache Tomcat 7.0.81 and prior versions are vulnerable.
NOTE: This issue is the result of an incomplete fix for the issue described in BID 100901 (Apache Tomcat CVE-2017-12615 Remote Code Execution Vulnerability).
Exploit / POC
Apache Tomcat CVE-2017-12617 Incomplete Fix Remote Code Execution Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Apache Tomcat CVE-2017-12617 Incomplete Fix Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Tomcat CVE-2017-12617 Incomplete Fix Remote Code Execution Vulnerability
References:
References:
- CVE-2017-12617 (Redhat)
- Apache Homepage (Apache)
- changelog.xml (Apache)
- Bug 1494283 - (CVE-2017-12617) CVE-2017-12617 tomcat: Remote Code Execution byp (Redhat)
- Bug 61542 - Apache Tomcat Remote Code Execution via JSP Upload bypass (Apache)
- Oracle Critical Patch Update Advisory - April 2018 (Oracle)
- Oracle Critical Patch Update Advisory - January 2018 (Oracle)
- SA156: Apache Tomcat Vulnerabilities Apr-Oct 2017 (Symantec)