{"schema_version":"1.7.5","id":"CVE-2017-12616","published":"2017-09-19T13:29:00.487Z","modified":"2026-07-08T05:49:31.142747496Z","aliases":["GHSA-8qq4-8jvq-mfw4"],"related":["SUSE-SU-2017:3059-1"],"details":"When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/tomcat","events":[{"introduced":"e498667bd7811e846771a852b16ce9f1e524b81b"},{"last_affected":"b44e3136d48b3debdd04b828e4b0e4fb96cc1f5e"}],"database_specific":{"cpe":["cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.3:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.4:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.5:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.7:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.8:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.9:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.13:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.14:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.15:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.16:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.17:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.18:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.19:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.20:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.21:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.22:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.23:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.24:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.25:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.26:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.27:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.28:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.29:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.30:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.31:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.32:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.33:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.34:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.35:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.36:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.37:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.38:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.39:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.40:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.41:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.42:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.43:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.44:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.45:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.46:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.47:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.48:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.49:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.50:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.51:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.54:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.55:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.56:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.57:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.58:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.59:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.60:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.61:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.62:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.63:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.64:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.65:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.66:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.67:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.68:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.69:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.70:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.71:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.72:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.73:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.74:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.75:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.76:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.77:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.79:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.80:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0.0"},{"last_affected":"7.0.0"},{"introduced":"7.0.1"},{"last_affected":"7.0.1"},{"introduced":"7.0.2"},{"last_affected":"7.0.2"},{"introduced":"7.0.3"},{"last_affected":"7.0.3"},{"introduced":"7.0.4"},{"last_affected":"7.0.4"},{"introduced":"7.0.5"},{"last_affected":"7.0.5"},{"introduced":"7.0.6"},{"last_affected":"7.0.6"},{"introduced":"7.0.7"},{"last_affected":"7.0.7"},{"introduced":"7.0.8"},{"last_affected":"7.0.8"},{"introduced":"7.0.9"},{"last_affected":"7.0.9"},{"introduced":"7.0.10"},{"last_affected":"7.0.10"},{"introduced":"7.0.11"},{"last_affected":"7.0.11"},{"introduced":"7.0.12"},{"last_affected":"7.0.12"},{"introduced":"7.0.13"},{"last_affected":"7.0.13"},{"introduced":"7.0.14"},{"last_affected":"7.0.14"},{"introduced":"7.0.15"},{"last_affected":"7.0.15"},{"introduced":"7.0.16"},{"last_affected":"7.0.16"},{"introduced":"7.0.17"},{"last_affected":"7.0.17"},{"introduced":"7.0.18"},{"last_affected":"7.0.18"},{"introduced":"7.0.19"},{"last_affected":"7.0.19"},{"introduced":"7.0.20"},{"last_affected":"7.0.20"},{"introduced":"7.0.21"},{"last_affected":"7.0.21"},{"introduced":"7.0.22"},{"last_affected":"7.0.22"},{"introduced":"7.0.23"},{"last_affected":"7.0.23"},{"introduced":"7.0.24"},{"last_affected":"7.0.24"},{"introduced":"7.0.25"},{"last_affected":"7.0.25"},{"introduced":"7.0.26"},{"last_affected":"7.0.26"},{"introduced":"7.0.27"},{"last_affected":"7.0.27"},{"introduced":"7.0.28"},{"last_affected":"7.0.28"},{"introduced":"7.0.29"},{"last_affected":"7.0.29"},{"introduced":"7.0.30"},{"last_affected":"7.0.30"},{"introduced":"7.0.31"},{"last_affected":"7.0.31"},{"introduced":"7.0.32"},{"last_affected":"7.0.32"},{"introduced":"7.0.33"},{"last_affected":"7.0.33"},{"introduced":"7.0.34"},{"last_affected":"7.0.34"},{"introduced":"7.0.35"},{"last_affected":"7.0.35"},{"introduced":"7.0.36"},{"last_affected":"7.0.36"},{"introduced":"7.0.37"},{"last_affected":"7.0.37"},{"introduced":"7.0.38"},{"last_affected":"7.0.38"},{"introduced":"7.0.39"},{"last_affected":"7.0.39"},{"introduced":"7.0.40"},{"last_affected":"7.0.40"},{"introduced":"7.0.41"},{"last_affected":"7.0.41"},{"introduced":"7.0.42"},{"last_affected":"7.0.42"},{"introduced":"7.0.43"},{"last_affected":"7.0.43"},{"introduced":"7.0.44"},{"last_affected":"7.0.44"},{"introduced":"7.0.45"},{"last_affected":"7.0.45"},{"introduced":"7.0.46"},{"last_affected":"7.0.46"},{"introduced":"7.0.47"},{"last_affected":"7.0.47"},{"introduced":"7.0.48"},{"last_affected":"7.0.48"},{"introduced":"7.0.49"},{"last_affected":"7.0.49"},{"introduced":"7.0.50"},{"last_affected":"7.0.50"},{"introduced":"7.0.51"},{"last_affected":"7.0.51"},{"introduced":"7.0.54"},{"last_affected":"7.0.54"},{"introduced":"7.0.55"},{"last_affected":"7.0.55"},{"introduced":"7.0.56"},{"last_affected":"7.0.56"},{"introduced":"7.0.57"},{"last_affected":"7.0.57"},{"introduced":"7.0.58"},{"last_affected":"7.0.58"},{"introduced":"7.0.59"},{"last_affected":"7.0.59"},{"introduced":"7.0.60"},{"last_affected":"7.0.60"},{"introduced":"7.0.61"},{"last_affected":"7.0.61"},{"introduced":"7.0.62"},{"last_affected":"7.0.62"},{"introduced":"7.0.63"},{"last_affected":"7.0.63"},{"introduced":"7.0.64"},{"last_affected":"7.0.64"},{"introduced":"7.0.65"},{"last_affected":"7.0.65"},{"introduced":"7.0.66"},{"last_affected":"7.0.66"},{"introduced":"7.0.67"},{"last_affected":"7.0.67"},{"introduced":"7.0.68"},{"last_affected":"7.0.68"},{"introduced":"7.0.69"},{"last_affected":"7.0.69"},{"introduced":"7.0.70"},{"last_affected":"7.0.70"},{"introduced":"7.0.71"},{"last_affected":"7.0.71"},{"introduced":"7.0.72"},{"last_affected":"7.0.72"},{"introduced":"7.0.73"},{"last_affected":"7.0.73"},{"introduced":"7.0.74"},{"last_affected":"7.0.74"},{"introduced":"7.0.75"},{"last_affected":"7.0.75"},{"introduced":"7.0.76"},{"last_affected":"7.0.76"},{"introduced":"7.0.77"},{"last_affected":"7.0.77"},{"introduced":"7.0.79"},{"last_affected":"7.0.79"},{"introduced":"7.0.80"},{"last_affected":"7.0.80"}],"source":"CPE_STRING"}}],"versions":["7.0.0","7.0.1","7.0.10","7.0.11","7.0.12","7.0.13","7.0.14","7.0.15","7.0.16","7.0.17","7.0.18","7.0.19","7.0.2","7.0.20","7.0.21","7.0.22","7.0.23","7.0.24","7.0.25","7.0.26","7.0.27","7.0.28","7.0.29","7.0.3","7.0.30","7.0.31","7.0.32","7.0.33","7.0.34","7.0.35","7.0.36","7.0.37","7.0.38","7.0.39","7.0.4","7.0.40","7.0.41","7.0.42","7.0.43","7.0.44","7.0.45","7.0.46","7.0.47","7.0.48","7.0.49","7.0.5","7.0.50","7.0.51","7.0.54","7.0.55","7.0.56","7.0.57","7.0.58","7.0.59","7.0.6","7.0.60","7.0.61","7.0.62","7.0.63","7.0.64","7.0.65","7.0.66","7.0.67","7.0.68","7.0.69","7.0.7","7.0.70","7.0.71","7.0.72","7.0.73","7.0.74","7.0.75","7.0.76","7.0.77","7.0.79","7.0.8","7.0.80","7.0.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-12616.json"}}],"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/1df9b4552464caa42047062fe7175da0da06c18ecc8daf99258bbda6%40%3Cannounce.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2018/06/msg00008.html"},{"type":"WEB","url":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03828en_us"},{"type":"WEB","url":"https://usn.ubuntu.com/3665-1/"},{"type":"WEB","url":"https://www.synology.com/support/security/Synology_SA_17_54_Tomcat"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/100897"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1039393"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:0465"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:0466"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20171018-0001/"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.2:beta:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.4:beta:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:7.0.5:beta:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0.0-beta"},{"last_affected":"7.0.0-beta"},{"introduced":"7.0.2-beta"},{"last_affected":"7.0.2-beta"},{"introduced":"7.0.4-beta"},{"last_affected":"7.0.4-beta"},{"introduced":"7.0.5-beta"},{"last_affected":"7.0.5-beta"}],"source":"CPE_STRING","vendor_product":"apache:tomcat"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}