Executive brief
Apache Tomcat allows remote code execution when HTTP PUT requests are enabled. An attacker can upload a specially crafted JSP file to the server, which can then be executed by requesting the file.
Affected products
- Apache Tomcat 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46, 7.0.0 to 7.0.81
Timeline
- 2022-03-25: disclosed: Publication date of the advisory.
- exploited: Reported as exploited in the wild.