Дата обнаружения
|
21/09/2017 |
Уровень угрозы
|
High |
Описание
|
An remote code-execution vulnerability was found in Apache Tomcat. These vulnerability can be exploited remotely via a specially designed HTTP request. By exploiting these vulnerability malicious users can remotely execute arbitrary code in the context of the affected application. Technical details This vulnerablity only affects systems with HTTP PUTs enabled, it could be exploited to upload a malicious JSP file to a targeted server. |
Пораженные продукты
|
Apache Tomcat version 9.0.1 |
Решение
|
Update to the latest version |
Первичный источник обнаружения
|
Apache Tomcat 8 vulnerabilities Apache Tomcat 8.5 vulnerabilities Apache Tomcat 9 vulnerabilities Apache Tomcat 7 vulnerabilities |
Оказываемое влияние
?
|
ACE
[?]
|
Связанные продукты
|
Apache Tomcat |
CVE-IDS
|
|
Эксплуатация
|
The following public exploits exists for this vulnerability: |
Узнай статистику распространения уязвимостей в твоем регионе |