QID 980957

QID 980957: Java (maven) Security Update for org.apache.tomcat.embed:tomcat-embed-core (GHSA-pjfr-qf3p-3q25)

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to GHSA-pjfr-qf3p-3q25 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980957

    Software Advisories
    Advisory ID Software Component Link
    GHSA-pjfr-qf3p-3q25 org.apache.tomcat.embed:tomcat-embed-core URL Logo github.com/advisories/GHSA-pjfr-qf3p-3q25