PT-2017-12601 · Apache+3 · Apache Tomcat+3

Xxlegend

·

Published

2017-08-16

·

Updated

2026-02-19

·

CVE-2017-12615

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 7.0.0 through 7.0.79
Description The issue allows an attacker to upload a JSP file to the server via a specially crafted request when HTTP PUTs are enabled, for example, by setting the readonly initialisation parameter of the Default to false. This JSP file can then be requested, and any code it contains would be executed by the server.
Recommendations For Apache Tomcat versions 7.0.0 through 7.0.79, update to version 7.0.81 to obtain a version that includes the fix for this issue. As a temporary workaround, consider disabling HTTP PUTs by setting the readonly initialisation parameter of the Default to true until a patch is applied. Restrict access to the server to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
APACHETOMCATCVE201712615CHECK
CESA-2017_3080
CESA-2017_3081
CVE-2017-12615
ELSA-2017-3080
ELSA-2017-3081
GHSA-PJFR-QF3P-3Q25
RHSA-2017:3080
RHSA-2017:3081
RHSA-2017:3113
RHSA-2017_3080
RHSA-2017_3081
RHSA-2018:0466
SUSE-SU-2017:3059-1
SUSE-SU-2017_3059-1

Affected Products

Apache Tomcat
Centos
Red Hat
Suse