Archived Content: This information is no longer maintained and is provided "as is" for your convenience.
Summary
Question
Is SiteScope affected by Tomcat vulnerability CVE-2017-12615?
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. Published: September 19, 2017; 09:29:00 AM -04:00 |
Answer
The version of tomcat for 11.33 is Apache Tomcat Version 7.0.69.
Analysing Tomcat CVE-2017-12615 for SiteScope.
It was clear from security experts that SiteScope is NOT affected by this vulnerabilities.