Apache Tomcat on Windows Remote Code Execution Vulnerability
High CVSS 8.1 Listed in CISA KEV
Summary
When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Apache:Tomcat
- :
- :
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2017-12615 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- http://breaktoprotect.blogspot.com/2017/09/the-case-of-cve-2017-12615-tomcat-7-put.html Exploit
- http://www.securityfocus.com/bid/100901 Broken Link
- http://www.securitytracker.com/id/1039392 Broken Link
- https://access.redhat.com/errata/RHSA-2017:3080 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3081 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3113 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3114 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0465 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0466 Third Party Advisory
- https://github.com/breaktoprotect/CVE-2017-12615 Exploit
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3E Mailing List
- https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3E Mailing List
- https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3E Mailing List
- https://lists.apache.org/thread.html/8fcb1e2d5895413abcf266f011b9918ae03e0b7daceb118ffbf23f8c%40%3Cannounce.tomcat.apache.org%3E Issue Tracking
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E Mailing List
- https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E Mailing List
- https://security.netapp.com/advisory/ntap-20171018-0001/ Third Party Advisory
- https://www.exploit-db.com/exploits/42953/ Third Party Advisory
- https://www.synology.com/support/security/Synology_SA_17_54_Tomcat Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12615 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD