Skip to main content
UNPWNED
CVE Radar
High Actively ExploitedMySQL

CVE-2017-12617

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVSS Base Score
8.1

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploit Probability
100%EPSS PERCENTILE0100

More exploitable than 100% of all CVEs · Top 0%

Is your site exposed to this?

Run a free scan. UNPWNED fingerprints your stack and flags this CVE class if the affected technology is detected.

Check my site
Details
Published
2017-10-04
Last modified
2026-08-25
Added to CISA KEV
2022-03-25
Affected
MySQL

Data from the National Vulnerability Database (NVD), CISA KEV, and FIRST.org EPSS. This product uses the NVD API but is not endorsed or certified by the NVD. EPSS is a probability estimate, not a guarantee of exploitation.