Количество 13
Количество 13
GHSA-xjgh-84hx-56c5
Unrestricted Upload of File with Dangerous Type Apache Tomcat

CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22 ...

BDU:2023-01045
Уязвимость сервера приложений Apache Tomcat, связанная с отсутствием ограничений на загрузку файлов, позволяющая нарушителю выполнить произвольный код

openSUSE-SU-2017:3069-1
Security update for tomcat

SUSE-SU-2021:14705-1
Security update for tomcat6

SUSE-SU-2017:3279-1
Security update for tomcat

SUSE-SU-2017:3039-1
Security update for tomcat
ELSA-2017-3081
ELSA-2017-3081: tomcat security update (IMPORTANT)
ELSA-2017-3080
ELSA-2017-3080: tomcat6 security update (IMPORTANT)

SUSE-SU-2017:3059-1
Security update for tomcat
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-xjgh-84hx-56c5 Unrestricted Upload of File with Dangerous Type Apache Tomcat | CVSS3: 8.1 | 94% Критический | около 3 лет назад | |
![]() | CVE-2017-12617 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. | CVSS3: 8.1 | 94% Критический | почти 8 лет назад |
![]() | CVE-2017-12617 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. | CVSS3: 8.1 | 94% Критический | почти 8 лет назад |
![]() | CVE-2017-12617 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. | CVSS3: 8.1 | 94% Критический | почти 8 лет назад |
CVE-2017-12617 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22 ... | CVSS3: 8.1 | 94% Критический | почти 8 лет назад | |
![]() | BDU:2023-01045 Уязвимость сервера приложений Apache Tomcat, связанная с отсутствием ограничений на загрузку файлов, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.1 | 94% Критический | почти 8 лет назад |
![]() | openSUSE-SU-2017:3069-1 Security update for tomcat | больше 7 лет назад | ||
![]() | SUSE-SU-2021:14705-1 Security update for tomcat6 | больше 4 лет назад | ||
![]() | SUSE-SU-2017:3279-1 Security update for tomcat | больше 7 лет назад | ||
![]() | SUSE-SU-2017:3039-1 Security update for tomcat | больше 7 лет назад | ||
ELSA-2017-3081 ELSA-2017-3081: tomcat security update (IMPORTANT) | почти 8 лет назад | |||
ELSA-2017-3080 ELSA-2017-3080: tomcat6 security update (IMPORTANT) | почти 8 лет назад | |||
![]() | SUSE-SU-2017:3059-1 Security update for tomcat | больше 7 лет назад |
Уязвимостей на страницу