EUVD-2022-5811
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 25 Mar 2022. Evidence sources: cisa_kev.
- ENISA score
- 8.1 · CVSS 3.1
- Advisory evidence
- 22 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_redhat · RHSA-2018:0466Red Hat Security Advisory: Red Hat JBoss Web Server 3.1.0 Service Pack 2 security update
- csaf_suse · SUSE-SU-2017:3059-1Security update for tomcat
- csaf_redhat · RHSA-2018:0268Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.4.19 security update
- csaf_redhat · RHSA-2017:3114Red Hat Security Advisory: Red Hat JBoss Web Server security and bug fix update
- csaf_redhat · RHSA-2017:3113Red Hat Security Advisory: Red Hat JBoss Web Server security and bug fix update
- csaf_suse · SUSE-SU-2017:3279-1Security update for tomcat
- csaf_redhat · RHSA-2017:3080Red Hat Security Advisory: tomcat6 security update
- csaf_redhat · RHSA-2018:0269Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.4.19 security update
- csaf_redhat · RHSA-2018:0275Red Hat Security Advisory: jboss-ec2-eap security, bug fix, and enhancement update
- csaf_redhat · RHSA-2018:0465Red Hat Security Advisory: Red Hat JBoss Web Server 3.1.0 Service Pack 2 security update
- csaf_redhat · RHSA-2017:3081Red Hat Security Advisory: tomcat security update
- csaf_redhat · RHSA-2018:0271Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.4.19 security update
- csaf_suse · SUSE-SU-2021:14705-1Security update for tomcat6
- csaf_redhat · RHSA-2018:0270Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 6.4.19 security update
- csaf_suse · SUSE-SU-2017:3039-1Security update for tomcat
- csaf_redhat · RHSA-2018:2939Red Hat Security Advisory: Red Hat FIS 2.0 on Fuse 6.3.0 R8 security and bug fix update
