KEVIntel
8.1
CVSS
High

CVE-2017-12615

PUBLISHED

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default...

Exploited in the wild Used in malware Remote No user interaction
Vendor
Apache Software Foundation
Product
Apache Tomcat
Published
Sep 19, 2017
EPSS

Description

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

apache windows cisa malware ransomware nuclei_scanner

CVSS scores

CVSS v3.1 8.1 High

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

Exploitation status

Exploited in the wild

Recorded 2022-03-25 00:00:00 UTC · Source

Used in malware

Recorded 2022-03-25 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Mar 25, 2022

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

wudidwo/CVE-2017-12615-poc

github · Created 2024-11-19 11:47:11 UTC · 0 stars

w0x68y/CVE-2017-12615-EXP

github · Created 2021-01-12 09:07:12 UTC · 1 stars

CVE-2017-12615 任意文件写入exp,写入webshell

cyberharsh/Tomcat-CVE-2017-12615

github · Created 2020-06-24 21:14:41 UTC · 0 stars

ianxtianxt/CVE-2017-12615

github · Created 2020-01-20 14:56:05 UTC · 1 stars

CVE-2017-12615 批量脚本

Shellkeys/CVE-2017-12615

github · Created 2018-04-01 15:22:51 UTC · 0 stars

tomcat7.x远程命令执行

1337g/CVE-2017-12615

github · Created 2017-12-26 03:48:14 UTC · 3 stars

CVE-2017-12615 Tomcat RCE (TESTED)

BeyondCy/CVE-2017-12615

github · Created 2017-11-28 02:51:16 UTC · 1 stars

Tomcat 远程代码执行漏洞 Exploit

zi0Black/POC-CVE-2017-12615-or-CVE-2017-12717

github · Created 2017-10-06 22:04:23 UTC · 5 stars

CVE-2017-12617 and CVE-2017-12615 for tomcat server

breaktoprotect/CVE-2017-12615

github · Created 2017-09-23 06:15:48 UTC · 111 stars

POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability.

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Nuclei