CVE-2017-12615

high

Description

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

References

https://github.com/chengbochuan3/CVE-Apache-Ecosystem

https://github.com/marez8505/VulnScout

https://github.com/netw0rk7/CVE-2017-12615-Home-Lab

https://github.com/RedTeamShanks/Local-Network-Vulnerability-Assessment

https://github.com/cyberwithcyril/VulhubPenTestingReport

https://github.com/wudidwo/CVE-2017-12615-poc

https://github.com/lizhianyuguangming/TomcatWeakPassChecker

https://github.com/lizhianyuguangming/TomcatScanPro

https://github.com/heane404/CVE_scan

https://github.com/xiaokp7/Tomcat_PUT_GUI_EXP

https://github.com/gk0d/CVE-2017-12615-POC-EXP

https://github.com/tpt11fb/AttackTomcat

https://github.com/w0x68y/CVE-2017-12615-EXP

https://github.com/gardenWhy/CVE-2017-12615-EXP

https://github.com/ianxtianxt/CVE-2017-12615

https://github.com/yafeile/CVE

https://github.com/advisories/GHSA-pjfr-qf3p-3q25

https://github.com/1337g/CVE-2017-12615

https://github.com/zi0Black/POC-CVE-2017-12615-or-CVE-2017-12717

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12615

https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E

https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E

https://lists.apache.org/thread.html/8fcb1e2d5895413abcf266f011b9918ae03e0b7daceb118ffbf23f8c%40%3Cannounce.tomcat.apache.org%3E

https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E

https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E

https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E

https://github.com/breaktoprotect/CVE-2017-12615

http://www.securitytracker.com/id/1039392

http://www.securityfocus.com/bid/100901

http://breaktoprotect.blogspot.com/2017/09/the-case-of-cve-2017-12615-tomcat-7-put.html

Details

Source: Mitre, NVD

Published: 2017-09-19

Updated: 2026-08-06

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 8.1

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.99607