PoC Index

CVE-2017-12615

KEV RANSOMWAREHIGH 8.1EPSS 99.6%

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVSS v3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.0
8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H
CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
99.61% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-03-25, used in ransomware campaigns
Nuclei
high · CWE-434
Published
2017-09-19
Updated
2026-08-06

Proof-of-concept exploits (18)

Nuclei templates (1)

ExploitDB entries (1)

Vulhub environments (1)

Exploit collections (2)

References

Related