KEVIntel
8.1
CVSS
High

CVE-2017-12617

PUBLISHED

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via...

Exploited in the wild Remote No user interaction
Vendor
Apache Software Foundation
Product
Apache Tomcat
Published
Oct 03, 2017
EPSS

Description

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

apache cisa nuclei_scanner metasploit

CVSS scores

CVSS v3.1 8.1 High

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

Exploitation status

Exploited in the wild

Recorded 2022-03-25 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

References

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Mar 25, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

tomcat_jsp_upload_bypass

metasploit · Created Unknown

Metasploit module for CVE-2017-12617

DevaDJ/CVE-2017-12617

github · Created 2024-12-13 11:22:38 UTC · 0 stars

Improved version of PikaChu CVE

yZeetje/CVE-2017-12617

github · Created 2024-07-04 07:23:39 UTC · 0 stars

CVE-2017-12617

scirusvulgaris/CVE-2017-12617

github · Created 2024-06-28 08:33:41 UTC · 0 stars

K3ysTr0K3R/CVE-2017-12617-EXPLOIT

github · Created 2024-03-18 20:10:46 UTC · 0 stars

LongWayHomie/CVE-2017-12617

github · Created 2021-12-10 22:21:07 UTC · 3 stars

CVE-2017-12617 is a critical vulnerability leading to Remote Code Execution (RCE) in Apache Tomcat.

ygouzerh/CVE-2017-12617

github · Created 2019-01-14 20:58:29 UTC · 2 stars

Proof of Concept - RCE Exploitation : Web Shell on Apache Tomcat - Ensimag January 2018

qiantu88/CVE-2017-12617

github · Created 2018-12-19 10:26:33 UTC · 0 stars

devcoinfet/CVE-2017-12617

github · Created 2018-02-09 01:02:32 UTC · 0 stars

Code put together from a few peoples ideas credit given don't use maliciously please

cyberheartmi9/CVE-2017-12617

github · Created 2017-10-05 23:41:52 UTC · 390 stars

Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit