Description
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- apache / Tomcat7.0.0 – 7.0.82
- Apache Software Foundation / Apache Tomcat8.5.0 to 8.5.22 – 8.5.0 to 8.5.22
- Apache Software Foundation / Apache Tomcat9.0.0.M1 to 9.0.0 – 9.0.0.M1 to 9.0.0
- Apache Software Foundation / Apache Tomcat8.0.0.RC1 to 8.0.46 – 8.0.0.RC1 to 8.0.46
- Apache Software Foundation / Apache Tomcat7.0.0 to 7.0.81 – 7.0.0 to 7.0.81
- Canonical / Ubuntu Linux12.04 – 12.04
- Canonical / Ubuntu Linux16.04 – 16.04
- Canonical / Ubuntu Linux17.10 – 17.10
- Canonical / Ubuntu Linux18.04 – 18.04
- debian / debian_linux7.0 – 7.0
- NETAPP / active_iq_unified_manager7.3 –
- NETAPP / active_iq_unified_manager9.5 –
- NETAPP / element
- NETAPP / oncommand_balance
- NETAPP / OnCommand Insight
- NETAPP / oncommand_shift
- NETAPP / OnCommand Workflow Automation
- NETAPP / SnapCenter
- oracle / agile_product_lifecycle_management9.3.6 – 9.3.6
- oracle / agile_product_lifecycle_management9.3.3 – 9.3.3
- oracle / agile_product_lifecycle_management9.3.4 – 9.3.4
- oracle / agile_product_lifecycle_management9.3.5 – 9.3.5
- oracle / communications_instant_messaging_server10.0.1 – 10.0.1
- oracle / endeca_information_discovery_integrator3.2.0 – 3.2.0
- oracle / endeca_information_discovery_integrator3.1.0 – 3.1.0
- oracle / enterprise_manager_for_mysql_database12.1.0.4.0 – 12.1.0.4.0
- oracle / financial_services_analytical_applications_infrastructure7.3.3.0.0 – 7.3.5.3.0
- oracle / fmw_platform12.2.1.2.0 – 12.2.1.2.0
- oracle / fmw_platform12.2.1.3.0 – 12.2.1.3.0
- oracle / health_sciences_empirica_inspections1.0.1.1 – 1.0.1.1
- oracle / hospitality_guest_access4.2.1 – 4.2.1
- oracle / hospitality_guest_access4.2.0 – 4.2.0
- oracle / instantis_enterprisetrack17.1 – 17.1
- oracle / instantis_enterprisetrack17.2 – 17.2
- oracle / management_pack11.2.1.0.13 – 11.2.1.0.13
- oracle / micros_lucas2.9.5 – 2.9.5
- oracle / micros_retail_xbri_loss_prevention10.8.1 – 10.8.1
- oracle / micros_retail_xbri_loss_prevention10.7.0 – 10.7.0
- oracle / micros_retail_xbri_loss_prevention10.6.0 – 10.6.0
- oracle / micros_retail_xbri_loss_prevention10.5.0 – 10.5.0
- oracle / micros_retail_xbri_loss_prevention10.0.1 – 10.0.1
- oracle / micros_retail_xbri_loss_prevention10.8.0 – 10.8.0
- oracle / MySQL Enterprise Monitor3.3.6.3293
- oracle / retail_advanced_inventory_planning14.1 – 14.1
- oracle / retail_advanced_inventory_planning13.4 – 13.4
- oracle / retail_advanced_inventory_planning13.2 – 13.2
- oracle / retail_advanced_inventory_planning15.0 – 15.0
- oracle / retail_back_office14.0.4 – 14.0.4
- oracle / retail_back_office14.1.3 – 14.1.3
- oracle / retail_central_office14.1.3 – 14.1.3
- oracle / retail_central_office14.0.4 – 14.0.4
- oracle / retail_convenience_and_fuel_pos_software2.1.132 – 2.1.132
- oracle / retail_eftlink1.1.124 – 1.1.124
- oracle / retail_eftlink15.0.1 – 15.0.1
- oracle / retail_eftlink16.0.2 – 16.0.2
- oracle / retail_insights14.1 – 14.1
- oracle / retail_insights15.0 – 15.0
- oracle / retail_insights16.0 – 16.0
- oracle / retail_insights14.0 – 14.0
- oracle / retail_invoice_matching14.1 – 14.1
- oracle / retail_invoice_matching15.0 – 15.0
- oracle / retail_invoice_matching16.0 – 16.0
- oracle / retail_invoice_matching14.0 – 14.0
- oracle / retail_invoice_matching13.2 – 13.2
- oracle / retail_invoice_matching13.1 – 13.1
- oracle / retail_invoice_matching13.0 – 13.0
- oracle / retail_invoice_matching12.0 – 12.0
- oracle / retail_order_broker15.0 – 15.0
- oracle / retail_order_broker5.0 – 5.0
- oracle / retail_order_broker16.0 – 16.0
- oracle / retail_order_broker5.1 – 5.1
- oracle / retail_order_broker5.2 – 5.2
- oracle / retail_order_management_system4.0 – 4.0
- oracle / retail_order_management_system5.0 – 5.0
- oracle / retail_order_management_system4.7 – 4.7
- oracle / retail_order_management_system4.5 – 4.5
- oracle / retail_point-of-service14.0.4 – 14.0.4
- oracle / retail_point-of-service14.1.3 – 14.1.3
- oracle / retail_price_management16.0 – 16.0
- oracle / retail_price_management15.0 – 15.0
- oracle / retail_price_management14.1 – 14.1
- oracle / retail_price_management14.0 – 14.0
- oracle / retail_price_management13.2 – 13.2
- oracle / retail_price_management13.1 – 13.1
- oracle / retail_price_management13.0 – 13.0
- oracle / retail_price_management12.0 – 12.0
- oracle / retail_returns_management2.3.8 – 2.3.8
- oracle / retail_returns_management2.4.9 – 2.4.9
- oracle / retail_returns_management14.0.4 – 14.0.4
- oracle / retail_returns_management14.1.3 – 14.1.3
- oracle / retail_store_inventory_management14.1.3 – 14.1.3
- oracle / retail_store_inventory_management15.0.2 – 15.0.2
- oracle / retail_store_inventory_management16.0.1 – 16.0.1
- oracle / retail_store_inventory_management12.0.12 – 12.0.12
- oracle / retail_store_inventory_management13.0.7 – 13.0.7
- oracle / retail_store_inventory_management13.1.9 – 13.1.9
- oracle / retail_store_inventory_management13.2.9 – 13.2.9
- oracle / retail_store_inventory_management14.0.4 – 14.0.4
- oracle / retail_xstore_point_of_service7.0.6 – 7.0.6
- oracle / retail_xstore_point_of_service7.1.6 – 7.1.6
- oracle / retail_xstore_point_of_service15.0.1 – 15.0.1
- oracle / retail_xstore_point_of_service6.0.11 – 6.0.11
- oracle / transportation_management6.3.3 – 6.3.3
- oracle / transportation_management6.3.1 – 6.3.1
- oracle / transportation_management6.3.2 – 6.3.2
- oracle / transportation_management6.3.7 – 6.3.7
- oracle / transportation_management6.3.6 – 6.3.6
- oracle / transportation_management6.3.5 – 6.3.5
- oracle / transportation_management6.3.4 – 6.3.4
- oracle / tuxedo_system_and_applications_monitor12.1.3.0.0 – 12.1.3.0.0
- oracle / webcenter_sites11.1.1.8.0 – 11.1.1.8.0
- oracle / workload_manager12.2.0.1 – 12.2.0.1
- RedHat / enterprise_linux_desktop7.0 – 7.0
- RedHat / enterprise_linux_desktop6.0 – 6.0
- RedHat / enterprise_linux_eus7.7 – 7.7
- RedHat / enterprise_linux_eus7.4 – 7.4
- RedHat / enterprise_linux_eus7.5 – 7.5
- RedHat / enterprise_linux_eus7.6 – 7.6
- RedHat / enterprise_linux_eus_compute_node7.4 – 7.4
- RedHat / enterprise_linux_eus_compute_node7.7 – 7.7
- RedHat / enterprise_linux_eus_compute_node7.6 – 7.6
- RedHat / enterprise_linux_eus_compute_node7.5 – 7.5
- RedHat / enterprise_linux_for_ibm_z_systems6.0_s390x – 6.0_s390x
- RedHat / enterprise_linux_for_ibm_z_systems7.0_s390x – 7.0_s390x
- RedHat / enterprise_linux_for_ibm_z_systems_eus7.4_s390x – 7.4_s390x
- RedHat / enterprise_linux_for_ibm_z_systems_eus7.5_s390x – 7.5_s390x
- RedHat / enterprise_linux_for_ibm_z_systems_eus7.6_s390x – 7.6_s390x
- RedHat / enterprise_linux_for_ibm_z_systems_eus7.7_s390x – 7.7_s390x
- RedHat / enterprise_linux_for_power_big_endian6.0_ppc64 – 6.0_ppc64
- RedHat / enterprise_linux_for_power_big_endian7.0_ppc64 – 7.0_ppc64
- RedHat / enterprise_linux_for_power_big_endian_eus7.7_ppc64 – 7.7_ppc64
- RedHat / enterprise_linux_for_power_big_endian_eus7.6_ppc64 – 7.6_ppc64
- RedHat / enterprise_linux_for_power_big_endian_eus7.5_ppc64 – 7.5_ppc64
- RedHat / enterprise_linux_for_power_big_endian_eus7.4_ppc64 – 7.4_ppc64
- RedHat / enterprise_linux_for_power_little_endian7.0 – 7.0
- RedHat / enterprise_linux_for_power_little_endian_eus7.5_ppc64le – 7.5_ppc64le
- RedHat / enterprise_linux_for_power_little_endian_eus7.6_ppc64le – 7.6_ppc64le
- RedHat / enterprise_linux_for_power_little_endian_eus7.7_ppc64le – 7.7_ppc64le
- RedHat / enterprise_linux_for_power_little_endian_eus7.4_ppc64le – 7.4_ppc64le
- RedHat / enterprise_linux_server6.0 – 6.0
- RedHat / enterprise_linux_server7.0 – 7.0
- RedHat / enterprise_linux_server_aus7.7 – 7.7
- RedHat / enterprise_linux_server_aus7.4 – 7.4
- RedHat / enterprise_linux_server_aus7.6 – 7.6
- RedHat / enterprise_linux_server_tus7.7 – 7.7
- RedHat / enterprise_linux_server_tus7.6 – 7.6
- RedHat / enterprise_linux_server_tus7.4 – 7.4
- RedHat / enterprise_linux_workstation7.0 – 7.0
- RedHat / enterprise_linux_workstation6.0 – 6.0
- RedHat / fuse1.0 – 1.0
- RedHat / jboss_enterprise_application_platform6.4.0 – 6.4.0
- RedHat / jboss_enterprise_application_platform6.0.0 – 6.0.0
- RedHat / jboss_enterprise_web_server3.0.0 – 3.0.0
- RedHat / jboss_enterprise_web_server2.0.0 – 2.0.0
- RedHat / jboss_enterprise_web_server_text-only_advisories
Exploits & proofs of concept
- exploit-dbTomcat - Remote Code Execution via JSP Upload Bypass (Metasploit)by Metasploit
- exploit-dbApache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (2)by intx0x80
- nucleiApache Tomcat - Remote Code Executionby pussycat0x
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2017:3113
- VENDOR_ADVISORYhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- VENDOR_ADVISORYhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2017:3080
- MISChttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03828en_us
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2018:0269
- EXPLOIThttps://www.exploit-db.com/exploits/42966/
- MISChttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03812en_us
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2018:0270
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2018:0271
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2017/11/msg00009.html
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2018:2939
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2018:0465
- VENDOR_ADVISORYhttps://usn.ubuntu.com/3665-1/
- VENDOR_ADVISORYhttp://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2018:0268
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2017:3114
- EXPLOIThttps://www.exploit-db.com/exploits/43008/
- MISChttp://www.securitytracker.com/id/1039552
- MISChttp://www.securityfocus.com/bid/100954
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2018:0275
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2018:0466
- MAILING_LISThttps://lists.apache.org/thread.html/3fd341a604c4e9eab39e7eaabbbac39c30101a022acc11dd09d7ebcb%40%3Cannounce.tomcat.apache.org%3E
- MISChttps://security.netapp.com/advisory/ntap-20171018-0002/
- MISChttps://security.netapp.com/advisory/ntap-20180117-0002/
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2017:3081
- MAILING_LISThttps://lists.apache.org/thread.html/eb6efa8d59c45a7a9eff94c4b925467d3b3fec8ba7697f3daa314b04%40%3Cdev.tomcat.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/5c0e00fd31efc11e147bf99d0f03c00a734447d3b131ab0818644cdb%40%3Cdev.tomcat.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E
- MISChttps://support.f5.com/csp/article/K53173544
- MAILING_LISThttps://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661%40%3Cdev.tomcat.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E
- VENDOR_ADVISORYhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- MAILING_LISThttps://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E
Updated 44m ago · 8 sources