{"id":"CVE-2017-7675","description":"The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypass security constraints using a specially crafted URL.","cvssScore":7.5,"cvssVersion":"3.0","cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cvssMetrics":[{"version":"3.0","score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":5,"vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-22"],"resolved":"MITIGATED-BY-RASP","published":"2017-08-11","lastModified":"2026-06-17","affectedProducts":[{"vendor":"apache","product":"tomcat","version":"8.5.0"},{"vendor":"apache","product":"tomcat","version":"8.5.1"},{"vendor":"apache","product":"tomcat","version":"8.5.2"},{"vendor":"apache","product":"tomcat","version":"8.5.3"},{"vendor":"apache","product":"tomcat","version":"8.5.4"},{"vendor":"apache","product":"tomcat","version":"8.5.5"},{"vendor":"apache","product":"tomcat","version":"8.5.6"},{"vendor":"apache","product":"tomcat","version":"8.5.7"},{"vendor":"apache","product":"tomcat","version":"8.5.8"},{"vendor":"apache","product":"tomcat","version":"8.5.9"},{"vendor":"apache","product":"tomcat","version":"8.5.10"},{"vendor":"apache","product":"tomcat","version":"8.5.11"},{"vendor":"apache","product":"tomcat","version":"8.5.12"},{"vendor":"apache","product":"tomcat","version":"8.5.13"},{"vendor":"apache","product":"tomcat","version":"8.5.14"},{"vendor":"apache","product":"tomcat","version":"8.5.15"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone1"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone10"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone11"},{"vendor":"apache","product":"tomcat","version":"9.0.0","update":"milestone12"}],"totalAffectedProducts":1,"references":[{"url":"https://github.com/apache/tomcat/commit/cf181edc9a8c239cde704cffc3c503425bdcae2b","source":"osv","tags":["WEB"]},{"url":"https://github.com/apache/tomcat/commit/dacb030b85fe0e0b3da87469e23d0f31252fdede","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc@%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/d3a5818e8af731bde6a05ef031ed3acc093c6dd7c4bfcc4936eafd6c%40%3Cannounce.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/d3a5818e8af731bde6a05ef031ed3acc093c6dd7c4bfcc4936eafd6c@%3Cannounce.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661%40%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661@%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/eb6efa8d59c45a7a9eff94c4b925467d3b3fec8ba7697f3daa314b04%40%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/eb6efa8d59c45a7a9eff94c4b925467d3b3fec8ba7697f3daa314b04@%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]}],"reasoning":{"decidingSource":"secure-rule-match","decidingReason":"Promoted to MITIGATED-BY-RASP (security rule): this CVE's weakness (CWE-22: Path Traversal) can be mitigated by an ARMR path-traversal security rule that blocks this class of attack at the JVM level, without requiring a CVE-specific patch.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.apache.tomcat:tomcat"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"Open-source Maven artifact indexed by OSV (Maven packages: org.apache.tomcat:tomcat). The source is public, which makes an ARMR patch rule a candidate; nothing here establishes that one can be written."},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"matched","status":"MITIGATED-BY-RASP","detail":"CWE-22 (Path Traversal) is mitigable by an ARMR path-traversal security rule.","decisive":true},{"rule":"below-action-threshold","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit-published","stage":"disposition","outcome":"skipped"}],"affectedProducts":[{"vendor":"apache","product":"tomcat","isKnown":true,"cpe":"cpe:2.3:a:apache:tomcat:8.5.0:*:*:*:*:*:*:*","source":"yaml"}],"affectedPackages":[{"name":"org.apache.tomcat:tomcat","introduced":"9.0.0.M1","fixed":"9.0.0.M22"},{"name":"org.apache.tomcat:tomcat","introduced":"8.5.0","fixed":"8.5.16"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"full","mechanisms":["security-rule"],"ruleClass":"path-traversal"},"action":{"state":"available","type":"security-rule"},"review":{"state":"automated","basis":"inferred"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.1014,"percentile":0.95389},"ssvc":{"available":false}}