When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
https://www.synology.com/support/security/Synology_SA_17_54_Tomcat
https://www.exploit-db.com/exploits/42953/
https://security.netapp.com/advisory/ntap-20171018-0001/
https://access.redhat.com/errata/RHSA-2018:0466
https://access.redhat.com/errata/RHSA-2018:0465
https://access.redhat.com/errata/RHSA-2017:3114
https://access.redhat.com/errata/RHSA-2017:3113
https://github.com/chengbochuan3/CVE-Apache-Ecosystem
https://github.com/marez8505/VulnScout
https://github.com/netw0rk7/CVE-2017-12615-Home-Lab
https://github.com/RedTeamShanks/Local-Network-Vulnerability-Assessment
https://github.com/cyberwithcyril/VulhubPenTestingReport
https://github.com/wudidwo/CVE-2017-12615-poc
https://github.com/lizhianyuguangming/TomcatWeakPassChecker
https://github.com/lizhianyuguangming/TomcatScanPro
https://github.com/heane404/CVE_scan
https://github.com/xiaokp7/Tomcat_PUT_GUI_EXP
https://github.com/gk0d/CVE-2017-12615-POC-EXP
https://github.com/tpt11fb/AttackTomcat
https://github.com/w0x68y/CVE-2017-12615-EXP
https://github.com/gardenWhy/CVE-2017-12615-EXP
https://github.com/ianxtianxt/CVE-2017-12615
https://github.com/yafeile/CVE
https://github.com/advisories/GHSA-pjfr-qf3p-3q25
https://github.com/1337g/CVE-2017-12615
https://github.com/zi0Black/POC-CVE-2017-12615-or-CVE-2017-12717
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12615
https://github.com/breaktoprotect/CVE-2017-12615
http://www.securitytracker.com/id/1039392
http://www.securityfocus.com/bid/100901
http://breaktoprotect.blogspot.com/2017/09/the-case-of-cve-2017-12615-tomcat-7-put.html