vulnerability

Huawei EulerOS: CVE-2017-12615: tomcat security update

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Sep 19, 2017
Added
Nov 30, 2017
Modified
Aug 13, 2025

Description

Two vulnerabilities were discovered in Tomcat where if a servlet context was configured with readonly=false and HTTP PUT requests were allowed, an attacker could upload a JSP file to that context and achieve code execution.

Solutions

huawei-euleros-2_0_sp1-upgrade-tomcathuawei-euleros-2_0_sp1-upgrade-tomcat-admin-webappshuawei-euleros-2_0_sp1-upgrade-tomcat-el-2.2-apihuawei-euleros-2_0_sp1-upgrade-tomcat-jsp-2.2-apihuawei-euleros-2_0_sp1-upgrade-tomcat-libhuawei-euleros-2_0_sp1-upgrade-tomcat-servlet-3.0-apihuawei-euleros-2_0_sp1-upgrade-tomcat-webapps
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.