CVE-2017-12616
HIGHApache Tomcat 7.0.0-7.0.80 - Exposure of Sensitive Information via VirtualDirContext
Title source: llmDescription
When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.
References (14)
Core 14
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1039393
Vendor Advisory x_refsource_confirm
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03828en_us
Various Sources x_refsource_confirm
https://www.synology.com/support/security/Synology_SA_17_54_Tomcat
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:0465
Vendor Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/3665-1/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/100897
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:0466
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20171018-0001/
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/1df9b4552464caa42047062fe7175da0da06c18ecc8daf99258bbda6%40%3Cannounce.tomcat.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2018/06/msg00008.html
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E
Scores
CVSS v3
7.5
EPSS
0.9064
EPSS Percentile
99.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (46)
apache/tomcat
7.0.0 (2 CPE variants)
apache/tomcat
7.0.1
apache/tomcat
7.0.2 (2 CPE variants)
apache/tomcat
7.0.3
apache/tomcat
7.0.4 (2 CPE variants)
apache/tomcat
7.0.5 (2 CPE variants)
apache/tomcat
7.0.6
apache/tomcat
7.0.7
apache/tomcat
7.0.8
apache/tomcat
7.0.9
... and 36 more
Published
Sep 19, 2017
Tracked Since
Feb 18, 2026