CVE-2017-12615

Confirmed PUBLISHED

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default...

Apache Software Foundation · Apache Tomcat
Exploited in the wild Used in malware PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.1 High EPSS 99.6%

At a Glance

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

nuclei_scanner malware apache windows ransomware cisa
CVE Published
Sep 19, 2017
Exploitation Reported
Mar 25, 2022
CVSS
8.1 High
EPSS
99.6%
Remote No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Apache Software Foundation
Apache Tomcat

7.0.0 to 7.0.79

Affected

CVE References

  • RHSA-2017:3113 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:3113
  • RHSA-2017:3080 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:3080
  • RHSA-2018:0465 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2018:0465
  • RHSA-2017:3114 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2017:3114
  • RHSA-2018:0466 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2018:0466
Show 14 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.