CVE-2017-12615
KEV RANSOMWAREHIGH 8.1EPSS 99.6%
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.0
- 8.1 HIGH
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 99.61% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-03-25, used in ransomware campaigns
- Nuclei
- high · CWE-434
- Published
- 2017-09-19
- Updated
- 2026-08-06
Proof-of-concept exploits (18)
- breaktoprotect/CVE-2017-12615112★ · 2022-10-09
- 1337g/CVE-2017-126153★ · 2017-12-26
- BeyondCy/CVE-2017-126151★ · 2017-10-18
- Seif-Naouali/Secu_Dev_21★ · 2020-01-20
- Yehender/tkpentest0★ · 2025-09-11
- ZapcoMan/TomcatVulnToolkit10★ · 2025-11-02
- cved-sources/cve-2017-126150★ · 2021-04-15
- cyberharsh/Tomcat-CVE-2017-126150★ · 2020-06-25
- edyekomu/CVE-2017-12615-PoC0★ · 2025-07-17
- ianxtianxt/CVE-2017-126151★ · 2020-01-20
- mefulton/cve-2017-1261511★ · 2017-10-01
- qiantu88/Tomcat-Exploit1★ · 2018-12-19
- w0x68y/CVE-2017-12615-EXP1★ · 2021-01-13
- wsg00d/cve-2017-126152★ · 2017-11-01
- wudidwo/CVE-2017-12615-poc0★ · 2024-11-19
- xiaokp7/Tomcat_PUT_GUI_EXP11★ · 2023-03-14
- zi0Black/POC-CVE-2017-12615-or-CVE-2017-127175★ · 2017-10-10
- K3ysTr0K3R/CVE-2017-12615
Nuclei templates (1)
ExploitDB entries (1)
Vulhub environments (1)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/tomcat-cve-2017-12615-rce.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2017/CVE-2017-12615.yaml