VYPR
High severity7.5NVD Advisory· Published Sep 19, 2017· Updated May 13, 2026

CVE-2017-12616

CVE-2017-12616

Description

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.tomcat:tomcat-catalinaMaven
>= 7.0.0, < 7.0.817.0.81

Affected products

1
  • Apache Software Foundation/Apache Tomcatv5
    Range: 7.0.0 to 7.0.80

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

23

News mentions

0

No linked articles in our index yet.