---
id: CVE-2017-12617
title: >-
  When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22,
  8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g
summary: >-
  When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22,
  8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via
  setting the readonly initialisation parameter of the Default servlet to false)
  it was possib…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
  - CWE-434
vendor: apache
product: tomcat
affected:
  - 'tomcat >= 7.0.0, < 7.0.82'
  - 'tomcat >= 8.0, < 8.0.47'
  - 'tomcat >= 8.5.0, < 8.5.23'
  - 'tomcat >= 9.0.0, < 9.0.1'
  - ubuntu_linux = 12.04
  - ubuntu_linux = 16.04
  - ubuntu_linux = 17.10
  - ubuntu_linux = 18.04
  - agile_product_lifecycle_management = 9.3.3
  - agile_product_lifecycle_management = 9.3.4
  - agile_product_lifecycle_management = 9.3.5
  - agile_product_lifecycle_management = 9.3.6
  - communications_instant_messaging_server = 10.0.1
  - endeca_information_discovery_integrator = 3.1.0
  - endeca_information_discovery_integrator = 3.2.0
  - enterprise_manager_for_mysql_database = 12.1.0.4.0
  - >-
    financial_services_analytical_applications_infrastructure >= 7.3.3.0.0, <=
    7.3.5.3.0
  - >-
    financial_services_analytical_applications_infrastructure >= 8.0.0.0.0, <=
    8.0.9.0.0
  - fmw_platform = 12.2.1.2.0
  - fmw_platform = 12.2.1.3.0
  - health_sciences_empirica_inspections = 1.0.1.1
  - hospitality_guest_access = 4.2.0
  - hospitality_guest_access = 4.2.1
  - instantis_enterprisetrack = 17.1
  - instantis_enterprisetrack = 17.2
  - management_pack = 11.2.1.0.13
  - micros_lucas = 2.9.5
  - micros_retail_xbri_loss_prevention = 10.0.1
  - micros_retail_xbri_loss_prevention = 10.5.0
  - micros_retail_xbri_loss_prevention = 10.6.0
  - micros_retail_xbri_loss_prevention = 10.7.0
  - micros_retail_xbri_loss_prevention = 10.8.0
  - micros_retail_xbri_loss_prevention = 10.8.1
  - mysql_enterprise_monitor <= 3.3.6.3293
  - 'mysql_enterprise_monitor >= 3.4.0, <= 3.4.4.4226'
  - 'mysql_enterprise_monitor >= 4.0.0, <= 4.0.0.5135'
  - retail_advanced_inventory_planning = 13.2
  - retail_advanced_inventory_planning = 13.4
  - retail_advanced_inventory_planning = 14.1
  - retail_advanced_inventory_planning = 15.0
  - retail_back_office = 14.0.4
  - retail_back_office = 14.1.3
  - retail_central_office = 14.0.4
  - retail_central_office = 14.1.3
  - retail_convenience_and_fuel_pos_software = 2.1.132
  - retail_eftlink = 1.1.124
  - retail_eftlink = 15.0.1
  - retail_eftlink = 16.0.2
  - retail_insights = 14.0
  - retail_insights = 14.1
  - retail_insights = 15.0
  - retail_insights = 16.0
  - retail_invoice_matching = 12.0
  - retail_invoice_matching = 13.0
  - retail_invoice_matching = 13.1
  - retail_invoice_matching = 13.2
  - retail_invoice_matching = 14.0
  - retail_invoice_matching = 14.1
  - retail_invoice_matching = 15.0
  - retail_invoice_matching = 16.0
  - retail_order_broker = 5.0
  - retail_order_broker = 5.1
  - retail_order_broker = 5.2
  - retail_order_broker = 15.0
  - retail_order_broker = 16.0
  - retail_order_management_system = 4.0
  - retail_order_management_system = 4.5
  - retail_order_management_system = 4.7
  - retail_order_management_system = 5.0
  - retail_point-of-service = 14.0.4
  - retail_point-of-service = 14.1.3
  - retail_price_management = 12.0
  - retail_price_management = 13.0
  - retail_price_management = 13.1
  - retail_price_management = 13.2
  - retail_price_management = 14.0
  - retail_price_management = 14.1
  - retail_price_management = 15.0
  - retail_price_management = 16.0
  - retail_returns_management = 2.3.8
  - retail_returns_management = 2.4.9
  - retail_returns_management = 14.0.4
  - retail_returns_management = 14.1.3
  - retail_store_inventory_management = 12.0.12
  - retail_store_inventory_management = 13.0.7
  - retail_store_inventory_management = 13.1.9
  - retail_store_inventory_management = 13.2.9
  - retail_store_inventory_management = 14.0.4
  - retail_store_inventory_management = 14.1.3
  - retail_store_inventory_management = 15.0.2
  - retail_store_inventory_management = 16.0.1
  - retail_xstore_point_of_service = 6.0.11
  - retail_xstore_point_of_service = 7.0.6
  - retail_xstore_point_of_service = 7.1.6
  - retail_xstore_point_of_service = 15.0.1
  - transportation_management = 6.3.1
  - transportation_management = 6.3.2
  - transportation_management = 6.3.3
  - transportation_management = 6.3.4
  - transportation_management = 6.3.5
patched:
  - tomcat 9.0.1
published: '2017-10-04'
updated: '2026-08-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-12617'
references:
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
    label: security@apache.org
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
    label: security@apache.org
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
    label: security@apache.org
  - url: 'http://www.securityfocus.com/bid/100954'
    label: security@apache.org
  - url: 'http://www.securitytracker.com/id/1039552'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:3080'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:3081'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:3113'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2017:3114'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2018:0268'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2018:0269'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2018:0270'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2018:0271'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2018:0275'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2018:0465'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2018:0466'
    label: security@apache.org
  - url: 'https://access.redhat.com/errata/RHSA-2018:2939'
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/3fd341a604c4e9eab39e7eaabbbac39c30101a022acc11dd09d7ebcb%40%3Cannounce.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/5c0e00fd31efc11e147bf99d0f03c00a734447d3b131ab0818644cdb%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/eb6efa8d59c45a7a9eff94c4b925467d3b3fec8ba7697f3daa314b04%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: 'https://lists.debian.org/debian-lts-announce/2017/11/msg00009.html'
    label: security@apache.org
  - url: 'https://security.netapp.com/advisory/ntap-20171018-0002/'
    label: security@apache.org
  - url: 'https://security.netapp.com/advisory/ntap-20180117-0002/'
    label: security@apache.org
  - url: 'https://support.f5.com/csp/article/K53173544'
    label: security@apache.org
  - url: >-
      https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03812en_us
    label: security@apache.org
  - url: >-
      https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03828en_us
    label: security@apache.org
  - url: 'https://usn.ubuntu.com/3665-1/'
    label: security@apache.org
  - url: 'https://www.exploit-db.com/exploits/42966/'
    label: security@apache.org
  - url: 'https://www.exploit-db.com/exploits/43008/'
    label: security@apache.org
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
    label: security@apache.org
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/100954'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1039552'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:3080'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:3081'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:3113'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:3114'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2018:0268'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2018:0269'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2018:0270'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2018:0271'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2018:0275'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2018:0465'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2018:0466'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2018:2939'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/3fd341a604c4e9eab39e7eaabbbac39c30101a022acc11dd09d7ebcb%40%3Cannounce.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/5c0e00fd31efc11e147bf99d0f03c00a734447d3b131ab0818644cdb%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/eb6efa8d59c45a7a9eff94c4b925467d3b3fec8ba7697f3daa314b04%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2017/11/msg00009.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20171018-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20180117-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.f5.com/csp/article/K53173544'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03812en_us
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03828en_us
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/3665-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/42966/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/43008/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12617
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.99988
epssPercentile: 0.99984
kev: true
kevDateAdded: '2022-03-25'
kevDueDate: '2022-04-15'
kevRansomware: false
exploited: true
exploitAvailable: true
ingestedAt: '2026-08-25T17:29:29.067Z'
exploits:
  exploitdb: true
  github: 10
  githubRepos:
    - 'https://github.com/cyberheartmi9/CVE-2017-12617'
    - 'https://github.com/devcoinfet/CVE-2017-12617'
    - 'https://github.com/qiantu88/CVE-2017-12617'
  metasploit:
    - exploit/multi/http/tomcat_jsp_upload_bypass
  nuclei:
    - CVE-2017-12617
  checkedAt: '2026-09-08T15:36:49.085Z'
---

## Overview

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

## Affected

- `tomcat >= 7.0.0, < 7.0.82`
- `tomcat >= 8.0, < 8.0.47`
- `tomcat >= 8.5.0, < 8.5.23`
- `tomcat >= 9.0.0, < 9.0.1`
- `ubuntu_linux = 12.04`
- `ubuntu_linux = 16.04`
- `ubuntu_linux = 17.10`
- `ubuntu_linux = 18.04`
- `agile_product_lifecycle_management = 9.3.3`
- `agile_product_lifecycle_management = 9.3.4`
- `agile_product_lifecycle_management = 9.3.5`
- `agile_product_lifecycle_management = 9.3.6`
- `communications_instant_messaging_server = 10.0.1`
- `endeca_information_discovery_integrator = 3.1.0`
- `endeca_information_discovery_integrator = 3.2.0`
- `enterprise_manager_for_mysql_database = 12.1.0.4.0`
- `financial_services_analytical_applications_infrastructure >= 7.3.3.0.0, <= 7.3.5.3.0`
- `financial_services_analytical_applications_infrastructure >= 8.0.0.0.0, <= 8.0.9.0.0`
- `fmw_platform = 12.2.1.2.0`
- `fmw_platform = 12.2.1.3.0`
- `health_sciences_empirica_inspections = 1.0.1.1`
- `hospitality_guest_access = 4.2.0`
- `hospitality_guest_access = 4.2.1`
- `instantis_enterprisetrack = 17.1`
- `instantis_enterprisetrack = 17.2`
- `management_pack = 11.2.1.0.13`
- `micros_lucas = 2.9.5`
- `micros_retail_xbri_loss_prevention = 10.0.1`
- `micros_retail_xbri_loss_prevention = 10.5.0`
- `micros_retail_xbri_loss_prevention = 10.6.0`
- `micros_retail_xbri_loss_prevention = 10.7.0`
- `micros_retail_xbri_loss_prevention = 10.8.0`
- `micros_retail_xbri_loss_prevention = 10.8.1`
- `mysql_enterprise_monitor <= 3.3.6.3293`
- `mysql_enterprise_monitor >= 3.4.0, <= 3.4.4.4226`
- `mysql_enterprise_monitor >= 4.0.0, <= 4.0.0.5135`
- `retail_advanced_inventory_planning = 13.2`
- `retail_advanced_inventory_planning = 13.4`
- `retail_advanced_inventory_planning = 14.1`
- `retail_advanced_inventory_planning = 15.0`
- `retail_back_office = 14.0.4`
- `retail_back_office = 14.1.3`
- `retail_central_office = 14.0.4`
- `retail_central_office = 14.1.3`
- `retail_convenience_and_fuel_pos_software = 2.1.132`
- `retail_eftlink = 1.1.124`
- `retail_eftlink = 15.0.1`
- `retail_eftlink = 16.0.2`
- `retail_insights = 14.0`
- `retail_insights = 14.1`
- `retail_insights = 15.0`
- `retail_insights = 16.0`
- `retail_invoice_matching = 12.0`
- `retail_invoice_matching = 13.0`
- `retail_invoice_matching = 13.1`
- `retail_invoice_matching = 13.2`
- `retail_invoice_matching = 14.0`
- `retail_invoice_matching = 14.1`
- `retail_invoice_matching = 15.0`
- `retail_invoice_matching = 16.0`
- `retail_order_broker = 5.0`
- `retail_order_broker = 5.1`
- `retail_order_broker = 5.2`
- `retail_order_broker = 15.0`
- `retail_order_broker = 16.0`
- `retail_order_management_system = 4.0`
- `retail_order_management_system = 4.5`
- `retail_order_management_system = 4.7`
- `retail_order_management_system = 5.0`
- `retail_point-of-service = 14.0.4`
- `retail_point-of-service = 14.1.3`
- `retail_price_management = 12.0`
- `retail_price_management = 13.0`
- `retail_price_management = 13.1`
- `retail_price_management = 13.2`
- `retail_price_management = 14.0`
- `retail_price_management = 14.1`
- `retail_price_management = 15.0`
- `retail_price_management = 16.0`
- `retail_returns_management = 2.3.8`
- `retail_returns_management = 2.4.9`
- `retail_returns_management = 14.0.4`
- `retail_returns_management = 14.1.3`
- `retail_store_inventory_management = 12.0.12`
- `retail_store_inventory_management = 13.0.7`
- `retail_store_inventory_management = 13.1.9`
- `retail_store_inventory_management = 13.2.9`
- `retail_store_inventory_management = 14.0.4`
- `retail_store_inventory_management = 14.1.3`
- `retail_store_inventory_management = 15.0.2`
- `retail_store_inventory_management = 16.0.1`
- `retail_xstore_point_of_service = 6.0.11`
- `retail_xstore_point_of_service = 7.0.6`
- `retail_xstore_point_of_service = 7.1.6`
- `retail_xstore_point_of_service = 15.0.1`
- `transportation_management = 6.3.1`
- `transportation_management = 6.3.2`
- `transportation_management = 6.3.3`
- `transportation_management = 6.3.4`
- `transportation_management = 6.3.5`

## Remediation

Upgrade past the affected range:

- `tomcat 9.0.1`
