When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12617
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2022-03-25), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 8.1 retained for reference. Confidence: HIGH.
- 79 internet-exposed hosts are running an affected version right now
- Actively exploited in the wild (CISA-KEV)
A fix is available — apply it.
79 internet-exposed hosts are running an affected version of CVE-2017-12617 right now.
EchelonGraph is the only CVE feed that fuses live vulnerability intelligence with its own live internet-exposure radar — so you see not just that a CVE is exploited, but how much of the internet is exposed to it right now.
- CVSS v3
- 8.1
- EG Score
- 9.0(high)
- EPSS
- 100.0%
- KEV
- ⚠ Exploited
Published
October 4, 2017
Last Modified
April 21, 2026
Advisory Details (7)
Auto-updated May 19, 2026Affected: Red Hat Enterprise Linux 7.
https://access.redhat.com/errata/RHSA-2018:0268Affected: Red Hat Enterprise Linux 7.
https://access.redhat.com/errata/RHSA-2017:3081Affected: Red Hat Enterprise Linux 6.
https://access.redhat.com/errata/RHSA-2017:3080Vendor Advisories for CVE-2017-12617(7)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- RHSA-2018:0275Red Hat Product SecurityHigh
Red Hat Security Advisory: jboss-ec2-eap security, bug fix, and enhancement update
- RHSA-2018:0271Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.4.19 security update
- RHSA-2018:0268Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.4.19 security update
- RHSA-2018:0270Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.4.19 security update
- RHSA-2018:0269Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.4.19 security update
- RHSA-2017:3113Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat JBoss Web Server security and bug fix update
- RHSA-2017:3114Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat JBoss Web Server security and bug fix update
Patch Availability(14)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | tomcat7-user (7.0.68-1ubuntu0.4+esm3) @ xenial | 2026-07-22 | ubuntu |
| ubuntu | tomcat8-user (8.0.32-1ubuntu1.6) @ xenial | 2026-07-22 | ubuntu |
| redhat | patch | 2018-10-17 | redhat |
| redhat | patch | 2018-03-07 | redhat |
| redhat | tomcat-vault-0:1.1.6-1.Final_redhat_1.1.ep7.el7 | 2018-03-07 | redhat |
| redhat | jboss-ec2-eap-0:7.5.19-2.Final_redhat_2.ep6.el6 | 2018-02-05 | redhat |
| redhat | picketlink-federation-0:2.5.4-20.SP18_redhat_1.1.ep6.el5 | 2018-02-05 | redhat |
| redhat | picketlink-federation-0:2.5.4-20.SP18_redhat_1.1.ep6.el7 | 2018-02-05 | redhat |
| redhat | picketlink-federation-0:2.5.4-20.SP18_redhat_1.1.ep6.el6 | 2018-02-05 | redhat |
| redhat | jbossweb | 2018-02-05 | redhat |
| redhat | tomcat7 | 2017-11-02 | redhat |
| redhat | tomcat7-0:7.0.54-28_patch_05.ep6.el7 | 2017-11-02 | redhat |
| redhat | tomcat-0:7.0.76-3.el7_4 | 2017-10-30 | redhat |
| redhat | tomcat6-0:6.0.24-111.el6_9 | 2017-10-30 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(2 across 1 ecosystem)
Maven(2)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-core | 7.0.0 ... 7.0.81 (56 versions) | 7.0.82 | — |
| org.apache.tomcat:tomcat-catalina | 7.0.0 ... 7.0.81 (56 versions) | 7.0.82 | — |
Additional Vendor Advisories
(7)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
- Red HatRHSA-2017:3080IMPORTANT2017-09-21
RHSA-2017:3080 — Important
- Red HatRHSA-2017:3081IMPORTANT2017-09-21
RHSA-2017:3081 — Important
- Red HatRHSA-2018:0465IMPORTANT2017-09-21
RHSA-2018:0465 — Important
- Red HatRHSA-2018:0466IMPORTANT2017-09-21
RHSA-2018:0466 — Important
- Red HatRHSA-2018:2939IMPORTANT2017-09-21
RHSA-2018:2939 — Important
- UbuntuUSN-3665-1HIGH
Tomcat vulnerabilities
- UbuntuUSN-7282-1HIGH
tomcat7 vulnerabilities
Data Freshness Timeline
(refreshed 48× in last 7d / 191× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 359 total refreshes for this CVE.
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 17:46 UTCEG score recompute
- 2026-07-22 17:46 UTCVendor advisory
- 2026-07-22 14:04 UTCEPSS rescore
- 2026-07-22 13:32 UTCVendor advisory
- 2026-07-22 09:19 UTCVendor advisory
- 2026-07-22 05:06 UTCVendor advisory
- 2026-07-22 00:45 UTCVendor advisory
- 2026-07-21 18:48 UTCEG score recompute
- 2026-07-21 18:48 UTCVendor advisory
- 2026-07-21 15:21 UTCEPSS rescore
- 2026-07-21 15:21 UTCEPSS rescore
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-21 14:35 UTCVendor advisory
- 2026-07-21 10:22 UTCVendor advisory
- 2026-07-21 06:08 UTCVendor advisory
- 2026-07-21 01:55 UTCVendor advisory
- 2026-07-20 21:42 UTCVendor advisory
- 2026-07-20 17:29 UTCVendor advisory
- 2026-07-20 13:16 UTCVendor advisory
- 2026-07-20 09:04 UTCVendor advisory
- 2026-07-20 04:50 UTCVendor advisory
- 2026-07-20 00:36 UTCVendor advisory
- 2026-07-19 20:21 UTCVendor advisory
- 2026-07-19 16:04 UTCVendor advisory
Show 75 moreShow fewer
- 2026-07-19 11:50 UTCVendor advisory
- 2026-07-19 07:37 UTCVendor advisory
- 2026-07-19 03:24 UTCVendor advisory
- 2026-07-18 23:10 UTCVendor advisory
- 2026-07-18 18:57 UTCVendor advisory
- 2026-07-18 14:45 UTCVendor advisory
- 2026-07-18 10:32 UTCVendor advisory
- 2026-07-18 06:19 UTCVendor advisory
- 2026-07-18 02:06 UTCVendor advisory
- 2026-07-17 21:53 UTCVendor advisory
- 2026-07-17 17:40 UTCVendor advisory
- 2026-07-17 13:27 UTCVendor advisory
- 2026-07-17 09:13 UTCEG score recompute
- 2026-07-17 09:13 UTCVendor advisory
- 2026-07-17 05:00 UTCVendor advisory
- 2026-07-17 00:47 UTCVendor advisory
- 2026-07-16 20:35 UTCVendor advisory
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 16:22 UTCVendor advisory
- 2026-07-16 12:09 UTCVendor advisory
- 2026-07-16 07:57 UTCVendor advisory
- 2026-07-16 03:44 UTCVendor advisory
- 2026-07-15 23:31 UTCVendor advisory
- 2026-07-15 19:18 UTCVendor advisory
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 15:05 UTCVendor advisory
- 2026-07-15 15:04 UTCCISA KEV update
- 2026-07-15 10:53 UTCVendor advisory
- 2026-07-15 06:40 UTCVendor advisory
- 2026-07-15 02:24 UTCVendor advisory
- 2026-07-14 22:10 UTCVendor advisory
- 2026-07-14 18:05 UTCCISA KEV update
- 2026-07-14 17:54 UTCVendor advisory
- 2026-07-14 13:35 UTCVendor advisory
- 2026-07-14 09:22 UTCVendor advisory
- 2026-07-14 05:09 UTCVendor advisory
- 2026-07-14 00:56 UTCVendor advisory
- 2026-07-13 20:43 UTCVendor advisory
- 2026-07-13 17:07 UTCCISA KEV update
- 2026-07-13 16:30 UTCVendor advisory
- 2026-07-13 12:15 UTCVendor advisory
- 2026-07-13 07:59 UTCVendor advisory
- 2026-07-13 03:46 UTCVendor advisory
- 2026-07-12 23:33 UTCVendor advisory
- 2026-07-12 19:20 UTCVendor advisory
- 2026-07-12 15:07 UTCVendor advisory
- 2026-07-12 10:53 UTCVendor advisory
- 2026-07-12 06:40 UTCVendor advisory
- 2026-07-12 02:27 UTCVendor advisory
- 2026-07-11 22:14 UTCVendor advisory
- 2026-07-11 18:01 UTCVendor advisory
- 2026-07-11 13:48 UTCVendor advisory
- 2026-07-11 09:35 UTCVendor advisory
- 2026-07-11 05:22 UTCVendor advisory
- 2026-07-11 01:09 UTCVendor advisory
- 2026-07-10 20:56 UTCVendor advisory
- 2026-07-10 17:52 UTCCISA KEV update
- 2026-07-10 16:43 UTCVendor advisory
- 2026-07-10 12:30 UTCVendor advisory
- 2026-07-10 08:16 UTCVendor advisory
- 2026-07-10 04:02 UTCVendor advisory
- 2026-07-09 23:48 UTCVendor advisory
- 2026-07-09 19:36 UTCVendor advisory
- 2026-07-09 19:06 UTCEPSS rescore
- 2026-07-09 15:23 UTCVendor advisory
- 2026-07-09 11:08 UTCVendor advisory
- 2026-07-09 06:55 UTCVendor advisory
- 2026-07-09 02:43 UTCVendor advisory
- 2026-07-08 22:29 UTCVendor advisory
- 2026-07-08 18:16 UTCVendor advisory
- 2026-07-08 14:03 UTCVendor advisory
- 2026-07-08 09:49 UTCVendor advisory
- 2026-07-08 05:37 UTCVendor advisory
- 2026-07-08 01:21 UTCVendor advisory
- 2026-07-07 21:09 UTCVendor advisory
Publicly available exploits
(7 references)Working exploit code is in the public domain (1 Metasploit module) (3 GitHub PoCs) (2 Exploit-DB entries). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCLongWayHomie/CVE-2017-12617First seen Dec 10, 2021
CVE-2017-12617 is a critical vulnerability leading to Remote Code Execution (RCE) in Apache Tomcat.
Open source ↗ - GitHub PoCygouzerh/CVE-2017-12617First seen Jan 14, 2019
Proof of Concept - RCE Exploitation : Web Shell on Apache Tomcat - Ensimag January 2018
Open source ↗ - Exploit-DBEDB-43008✓ verifiedFirst seen Oct 17, 2017
Tomcat - Remote Code Execution via JSP Upload Bypass (Metasploit)
Open source ↗ - Exploit-DBEDB-42966✓ verifiedFirst seen Oct 9, 2017
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (2)
Open source ↗ - GitHub PoCcyberheartmi9/CVE-2017-12617First seen Oct 5, 2017
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution
Open source ↗ - Metasploitexploit/multi/http/tomcat_jsp_upload_bypass✓ verifiedFirst seen Oct 3, 2017
Tomcat RCE via JSP Upload Bypass
Open source ↗ - Nucleihttp/cves/2017/CVE-2017-12617.yamlFirst seen Jan 1, 2017
Apache Tomcat - Remote Code Execution
Open source ↗
Frequently asked(6)
What is CVE-2017-12617?
When was CVE-2017-12617 disclosed?
Is CVE-2017-12617 actively exploited?
What is the CVSS score of CVE-2017-12617?
Which products are affected by CVE-2017-12617?
How do I remediate CVE-2017-12617?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2017-12617
Is Your Infrastructure Affected by CVE-2017-12617?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.