It was discovered that Tomcat incorrectly handled being configured with HTTP PUTs enabled. A remote attacker could use this issue to upload a JSP file to the server and execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-12616, CVE-2017-12617)
Continue reading...
Continue reading...

