All errata/sisyphus/ALT-PU-2017-2666-2
ALT-PU-2017-2666-2

Package update tomcat in branch sisyphus

Version8.0.47-alt1_2jpp8
Published2026-02-04
Max severityHIGH
Severity:

Closed issues (3)

BDU:2023-01045
HIGH8.1

Уязвимость сервера приложений Apache Tomcat, связанная с отсутствием ограничений на загрузку файлов, позволяющая нарушителю выполнить произвольный код

Published: 2023-03-06Modified: 2025-02-06
CVSS 3.xHIGH 8.1
CVSS:3.x/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.0CRITICAL 9.3
CVSS:2.0/AV:N/AC:M/Au:N/C:C/I:C/A:C
CVE-2017-12617
HIGH8.1

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Published: 2017-10-04Modified: 2026-04-21
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS 3.xHIGH 8.1
CVSS:3.x/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
References
GHSA-xjgh-84hx-56c5
HIGH8.1

Unrestricted Upload of File with Dangerous Type Apache Tomcat

Published: 2022-05-14Modified: 2025-10-22
CVSS 3.xHIGH 8.1
CVSS:3.x/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H
References