CVE-2017-12616 is a high-severity vulnerability affecting Apache Tomcat versions 7.0.0 to 7.0.80 when using VirtualDirContext. It allows attackers to bypass security constraints or view JSP source code via specially crafted requests. With a CVSS score of 7.5 (High), this vulnerability has a network attack vector, low attack complexity, and high confidentiality impact, potentially exposing sensitive information. Despite its high EPSS and FAUCET risk scores, there is no evidence of active exploitation, nor are there public exploits available in common databases like Metasploit or ExploitDB. Community discussion and media coverage are minimal, suggesting limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:* | ||
7.0.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:* | ||
7.0.2CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:7.0.2:*:*:*:*:*:*:* | ||
7.0.2CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:7.0.2:beta:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.