CISA KEV 정보
| 취약점명 | Apache Tomcat Remote Code Execution Vulnerability |
|---|---|
| 설명 | When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. |
| 조치사항 | Apply updates per vendor instructions. |
| 랜섬웨어 캠페인 악용 | Unknown |
| CWE | CWE-434 |
| 등록일 (KEV) | 2022-03-25 |
| 조치 기한 | 2022-04-15 |
| 추가 참고 | https://nvd.nist.gov/vuln/detail/CVE-2017-12617 |
NVD 상세 정보
CVSS v3.1: 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS v2.0: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P설명: When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CWE: CWE-434 | CWE-434
참조
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html [Patch, Third Party Advisory]
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html [Patch, Third Party Advisory]
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html [Patch, Third Party Advisory]
- http://www.securityfocus.com/bid/100954 [Third Party Advisory, VDB Entry]
- http://www.securitytracker.com/id/1039552 [Third Party Advisory, VDB Entry]
- https://access.redhat.com/errata/RHSA-2017:3080 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2017:3081 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2017:3113 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2017:3114 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2018:0268 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2018:0269 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2018:0270 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2018:0271 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2018:0275 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2018:0465 [Third Party Advisory]
- ... 외 74건
This product uses the NVD API but is not endorsed or certified by the NVD.