PT-2017-12601 · Apache+3 · Apache Tomcat+3

Xxlegend

·

Publicado

2017-08-16

·

Atualizado

2026-02-19

·

CVE-2017-12615

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 7.0.0 through 7.0.79
Description The issue allows an attacker to upload a JSP file to the server via a specially crafted request when HTTP PUTs are enabled, for example, by setting the readonly initialisation parameter of the Default to false. This JSP file can then be requested, and any code it contains would be executed by the server.
Recommendations For Apache Tomcat versions 7.0.0 through 7.0.79, update to version 7.0.81 to obtain a version that includes the fix for this issue. As a temporary workaround, consider disabling HTTP PUTs by setting the readonly initialisation parameter of the Default to true until a patch is applied. Restrict access to the server to minimize the risk of exploitation.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
APACHETOMCATCVE201712615CHECK
CESA-2017_3080
CESA-2017_3081
CVE-2017-12615
ELSA-2017-3080
ELSA-2017-3081
GHSA-PJFR-QF3P-3Q25
RHSA-2017:3080
RHSA-2017:3081
RHSA-2017:3113
RHSA-2017_3080
RHSA-2017_3081
RHSA-2018:0466
SUSE-SU-2017:3059-1
SUSE-SU-2017_3059-1

Produtos afetados

Apache Tomcat
Centos
Red Hat
Suse