peter bassill · operator
$ cve CVE-2017-12615 JSON

CVE-2017-12615 KEV EXPLOIT

8.1
HIGH · CVSS 3.1 · EPSS 99.6% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.64% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-434
On CISA KEVyes — remediate by 2022-04-15
Public exploityes
Published2017-09-19
Last modified2026-08-06

CISA KEV

NameApache Tomcat on Windows Remote Code Execution Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productApache / Tomcat
Ransomware useknown

Affected (23)

VendorProduct
apachetomcat
microsoftwindows
netapp7-mode transition tool
netapponcommand balance
netapponcommand shift
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux eus compute node
redhatenterprise linux for ibm z systems
redhatenterprise linux for ibm z systems eus
redhatenterprise linux for power big endian
redhatenterprise linux for power big endian eus
redhatenterprise linux for power little endian
redhatenterprise linux for power little endian eus
redhatenterprise linux for scientific computing
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server for power little endian update services for sap solutions
redhatenterprise linux server tus
redhatenterprise linux server update services for sap solutions
redhatenterprise linux workstation
redhatjboss enterprise web server
redhatjboss enterprise web server text-only advisories

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD