CVE-2017-15706Improperly Implemented Security Check for Standard in Apache Tomcat

Severity
5.3MEDIUMNVD
EPSS
3.3%
top 12.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31
Latest updateMay 14

Description

As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script to execute. The update was not correct. As a result, some scripts may have failed to execute as expected and other scripts may have been executed unexpectedly. Note that the behaviour of the CGI servlet has remained unchanged in this regard. It is o

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDapache/tomcat7.0.797.0.82+4

🔴Vulnerability Details

5
OSV
Inconsistent documentation in Apache Tomcat2022-05-14
GHSA
Inconsistent documentation in Apache Tomcat2022-05-14
OSV
tomcat7, tomcat8 vulnerabilities2018-05-30
CVEList
CVE-2017-15706: As part of the fix for bug 61201, the documentation for Apache Tomcat 92018-01-31
OSV
CVE-2017-15706: As part of the fix for bug 61201, the documentation for Apache Tomcat 92018-01-31

📋Vendor Advisories

4
Ubuntu
Tomcat vulnerabilities2018-05-30
Red Hat
tomcat: Incorrect documentation of CGI Servlet search algorithm may lead to misconfiguration2018-01-31
Debian
CVE-2017-15706: tomcat9 - As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 ...2017
Apache
Apache tomcat: CVE-2017-15706

💬Community

3
Bugzilla
CVE-2017-15706 tomcat: Incorrect documentation of CGI Servlet search algorithm may lead to misconfiguration [epel-6]2018-02-01
Bugzilla
CVE-2017-15706 tomcat: Incorrect documentation of CGI Servlet search algorithm may lead to misconfiguration [fedora-all]2018-02-01
Bugzilla
CVE-2017-15706 tomcat: Incorrect documentation of CGI Servlet search algorithm may lead to misconfiguration2018-02-01
CVE-2017-15706 — Apache Tomcat vulnerability | cvebase