S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 10, 2024

CVE-2017-12617 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in Apache Tomcat affects v. 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2017-12617
8.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache Tomcatby Apache Software Foundation
9.0.0.M1 to 9.0.0
Updated Aug 22, 2026View on NVD →
Detail

Apache Tomcat is a widely used open-source web server and servlet container software. It provides a Java Platform Enterprise Edition (Java EE) environment for running Java code on web servers. Apache Tomcat is used for deploying, running and managing Java web applications on servers. Tomcat is also used to support various web technologies such as JSP, JDBC and JNDI. It is a trusted and popular choice for web developers and IT professionals.

CVE-2017-12617 is a vulnerability that was detected in Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81. This vulnerability can be exploited by attackers to upload a JSP file to the server through HTTP PUT requests. This payload can then execute any malicious code that hackers inject into it. The vulnerability is caused by a misconfiguration of the Default servlet that does not restrict the certain files or directories in place.

Exploiting CVE-2017-12617 can lead to serious consequences. Attackers have the ability to execute arbitrary code on the server which can compromise the entire infrastructure. With this vulnerability, attackers can gain access to sensitive information like user data, customer details, financial information, and other confidential data stored on the server. They can then modify, delete, or steal confidential data. Attackers can also launch bigger attacks by exploiting the server to target other systems or organizations.

In conclusion, security should be taken seriously when it comes to using Apache Tomcat. Thanks to the pro features offered by s4e.io, one can easily and quickly learn about vulnerabilities in their digital assets. The platform provides users with recommended mitigations and patches to help secure their infrastructure. With s4e.io, users can minimize the risk of attacks, protect against vulnerabilities, and stay ahead of emerging threat trends.

 

REFERENCES

Solution Advice

Apache Tomcat users can protect themselves against CVE-2017-12617 by taking a number of precautions. Here are some of the precautions that can be taken to protect against this vulnerability:

  • Upgrade the Apache Tomcat version to the latest version.
  • Disable the HTTP PUT method in Tomcat.
  • Restrict the ability to upload files to the server.
  • Use stronger and unique passwords for all accounts.
  • Use a web application firewall (WAF) to block malicious traffic.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-12617 scanner - Remote Code Execution (RCE) vulnerability in Apache Tomcat | S4E