← Browse

CVE-2017-12615

Act now ● On CISA KEV — actively exploited used in ransomware

Actively exploited — on the CISA KEV list.

CVSS base
8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
99.6%
99.9th percentile
CISA KEV
Listed
Added 2022-03-25 · patch by 2022-04-15
Weakness / dates
CWE-434
Published 2017-09-19 · modified 2026-08-06

CVSS breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack VectorNNetwork
Attack ComplexityHHigh
Privileges RequiredNNone
User InteractionNNone
ScopeUUnchanged
ConfidentialityHHigh
IntegrityHHigh
AvailabilityHHigh

Timeline

Description

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Affected

apache microsoft netapp redhat

References

Official: NVD · CVE.org