← All CVEs

CVE-2017-12615

high · 8.1Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-25Remediation due 2022-04-15

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

8.1
CVSS
99.6%
EPSS (exploit prob.)
100th
EPSS percentile
2017-09-19
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

Affected products

VendorProductAffected versions
apachetomcat>= 7.0.0, <= 7.0.79
microsoftwindowsall versions
netapp7-mode_transition_toolall versions
netapponcommand_balanceall versions
netapponcommand_shiftall versions
redhatenterprise_linux_server_update_services_for_sap_solutions7.4
redhatenterprise_linux_server_update_services_for_sap_solutions7.6
redhatenterprise_linux_server_update_services_for_sap_solutions7.7
redhatjboss_enterprise_web_server2.0.0
redhatjboss_enterprise_web_server3.0.0
redhatjboss_enterprise_web_server_text-only_advisoriesall versions
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_eus7.4
redhatenterprise_linux_eus7.5
redhatenterprise_linux_eus7.6
redhatenterprise_linux_eus7.7
redhatenterprise_linux_eus_compute_node7.4
redhatenterprise_linux_eus_compute_node7.5
redhatenterprise_linux_eus_compute_node7.6
redhatenterprise_linux_eus_compute_node7.7
redhatenterprise_linux_for_ibm_z_systems7.0_s390x
redhatenterprise_linux_for_ibm_z_systems_eus7.4_s390x
redhatenterprise_linux_for_ibm_z_systems_eus7.5_s390x
redhatenterprise_linux_for_ibm_z_systems_eus7.6_s390x
redhatenterprise_linux_for_ibm_z_systems_eus7.7_s390x
redhatenterprise_linux_for_power_big_endian7.0_ppc64
redhatenterprise_linux_for_power_big_endian_eus7.4_ppc64
redhatenterprise_linux_for_power_big_endian_eus7.5_ppc64
redhatenterprise_linux_for_power_big_endian_eus7.6_ppc64
redhatenterprise_linux_for_power_big_endian_eus7.7_ppc64
redhatenterprise_linux_for_power_little_endian7.0_ppc64le
redhatenterprise_linux_for_power_little_endian_eus7.4_ppc64le
redhatenterprise_linux_for_power_little_endian_eus7.5_ppc64le
redhatenterprise_linux_for_power_little_endian_eus7.6_ppc64le
redhatenterprise_linux_for_power_little_endian_eus7.7_ppc64le
redhatenterprise_linux_for_scientific_computing7.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server7.0
redhatenterprise_linux_server_aus7.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-12615