CVE-2017-12615

Aliases:GHSA-pjfr-qf3p-3q25
Advisory lineage Upstream: 0 Downstream: 5
Analyzed
Published: 19 Sept 2017, 13:00
Last modified:21 Oct 2025, 23:55

Vulnerability Summary

Overall Risk (default)
high
61/100
CVSS Score
8.1 HIGH
v3.1 (cve.org)
EPSS Score
94.23% CRITICAL
94% probability -0.05%
KEV
Listed
CISA
1 listing
Ransomware
Known Use
Public exploits
3 found
Dark Web
Not detected

Timeline

19 Sept 2017, 13:00
Published
Vulnerability first disclosed
25 Mar 2022, 00:00
Added to CISA KEV
Apache Tomcat on Windows Remote Code Execution Vulnerability
15 Apr 2022, 00:00
CISA Remediation Due
Apply updates per vendor instructions.
21 Oct 2025, 23:55
Last Modified
Vulnerability information updated

Description

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v3.0HIGHScore: 8.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 94.23% Percentile: 100%

Techniques & Countermeasures

  • CWE-434Unrestricted Upload of File with Dangerous Type

    The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Affected Systems

  • apache software foundationapache tomcat

    7.0.0 to 7.0.79

  • UnknownTomcat

    ≥ 7.0.0, ≤ 7.0.79

  • org.apache.tomcat.embedtomcat-embed-core

    ≥ 7.0.0, < 7.0.79

  • netapp7-mode_transition_tool

    na

  • netapponcommand_balance

    na

  • netapponcommand_shift

    na

  • redhatenterprise_linux_desktop

    6.0 | 7.0

  • redhatenterprise_linux_eus

    7.4 | 7.5 | 7.6 | 7.7

  • redhatenterprise_linux_eus_compute_node

    7.4 | 7.5 | 7.6 | 7.7

  • redhatenterprise_linux_for_ibm_z_systems

    7.0_s390x

  • redhatenterprise_linux_for_ibm_z_systems_eus

    7.4_s390x | 7.5_s390x | 7.6_s390x | 7.7_s390x

  • redhatenterprise_linux_for_power_big_endian

    7.0_ppc64

  • redhatenterprise_linux_for_power_big_endian_eus

    7.4_ppc64 | 7.5_ppc64 | 7.6_ppc64 | 7.7_ppc64

  • redhatenterprise_linux_for_power_little_endian

    7.0_ppc64le

  • redhatenterprise_linux_for_power_little_endian_eus

    7.4_ppc64le | 7.5_ppc64le | 7.6_ppc64le | 7.7_ppc64le

  • redhatenterprise_linux_for_scientific_computing

    7.0

  • redhatenterprise_linux_server

    6.0 | 7.0

  • redhatenterprise_linux_server_aus

    7.4 | 7.6 | 7.7

  • redhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions

    7.4_ppc64le | 7.6_ppc64le | 7.7_ppc64le | 9.2_ppc64le

  • redhatenterprise_linux_server_tus

    7.4 | 7.6 | 7.7

  • redhatenterprise_linux_server_update_services_for_sap_solutions

    7.4 | 7.6 | 7.7

  • redhatenterprise_linux_workstation

    6.0 | 7.0

  • redhatjboss_enterprise_web_server

    2.0.0 | 3.0.0

  • redhatjboss_enterprise_web_server_text-only_advisories

    na

References (30)