CVE-2017-12617CISA KEVEPSS p100.0%

CVE-2017-12617Apache Tomcat Remote Code Execution Vulnerability

Apache / Tomcat

Description

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Scoring

EPSS99.99% probability of exploitation · percentile 100.0% · 2026-06-15T12:03:41Z

CISA KEV entry

Added to KEV: 2022-03-25

(incoming)1

TypeTargetConfidenceTier
KEVEntryApache Tomcat Remote Code Execution Vulnerabilitykev-cve-2017-126170%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Apache Tomcat on Windows Remote Code Execution Vulnerability
CVE
Apache Struts Remote Code Execution Vulnerability
CVE
Apache Tomcat Path Equivalence Vulnerability
CVE
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
CVE
Red Hat JBoss Application Server Remote Code Execution Vulnerability
CVE
Apache Tomcat Improper Privilege Management Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.