CVE-2017-12617, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12617, the vulnerability affects only if:
- Tomcat is configured in readonly=false mode. This requires a specific setting in conf/web.xml to be set, which Ubisecure SSO does not do.
- WebDAV servlet is used and is configured in readonly=false mode. Ubisecure SSO doesn’t use WebDAV servlet.”
About The Author: Juha Koponen
Juha is Operations Manager at Ubisecure.
More posts by Juha Koponen