Junglewise Threat Intelligence

CVE-2017-12615: When running Apache Tomcat on Windows with HTTP PUTs enabled it was possible to upload a JSP file to the server

CVE-2017-12615 · Severity: critical · CVSS 3 · Exploited in the wild · Published 2018-10-17

Technologies: Apache Tomcat. Vendors: Maven, Apache.

Executive brief

Apache Tomcat on Windows allows remote code execution when HTTP PUT is enabled. An attacker can upload a specially crafted JSP file to the server, which can then be executed by the server upon request.

Affected products

  • Apache Tomcat 7.0.0 to 7.0.79

Timeline

  • 2017-09-19: disclosed: Initial public disclosure and exploit availability.
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats