cbcvebase.
CVE-2017-12615
published 2017-09-19

CVE-2017-12615: When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false)…

PriorityP195high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
99.61%
99.9th percentile
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
apachetomcat7.0.0 – 7.0.79
apache_software_foundationapache_tomcat
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus_compute_node
redhatenterprise_linux_eus_compute_node
redhatenterprise_linux_eus_compute_node
redhatenterprise_linux_eus_compute_node
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_power_big_endian
redhatenterprise_linux_for_power_big_endian_eus
redhatenterprise_linux_for_power_big_endian_eus
redhatenterprise_linux_for_power_big_endian_eus
redhatenterprise_linux_for_power_big_endian_eus
redhatenterprise_linux_for_power_little_endian
redhatenterprise_linux_for_power_little_endian_eus
redhatenterprise_linux_for_power_little_endian_eus

Detection & IOCsextracted from sources · hover to see the quote

hash14f8dc79113b6a2d3f378d2046dbc4a9a7c605ce24cfa5ef9f4e8f5406cfd84d
hash3596e8fa5e19e860a2029fa4ab7a4f95fadf073feb88e4f82b19a093e1e2737c
hash4bc1a84ddbbb360e3026e8ec1d0e1eff02a100cf01888e7e2a2ac6a105c71450
hashaa259b168ec448349e91a9d560569bdb6fabd811d78888c6080065a549f60cb0
pathC:\inetpub\
pathC:\xampp\
pathC:\wamp\
pathC:\phpStudy\PHPTutorial\WWW\
port445
port139
  • Detect HTTP PUT requests uploading JSP files to Apache Tomcat — the CVE-2017-12615 exploit uploads a JSP file via a specially crafted HTTP PUT request to achieve RCE. Trend Micro DDI rule 2498 covers this: 'CVE-2017-12615 - APACHE TOMCAT Remote Code Execution via JSP Upload - HTTP (Request)'.
  • Monitor for new JSP file creation under web server document roots (e.g. C:\inetpub\, C:\xampp\, C:\wamp\, C:\phpStudy\PHPTutorial\WWW\) — BlackSquid drops JSP webshells into these paths after exploiting CVE-2017-12615.
  • Check Point IPS blade signature 'Apache Tomcat PUT Method Arbitrary File Upload Remote Code Execution (CVE-2017-12615)' can be used for network-level detection of exploit attempts.
  • ·CVE-2017-12615 is only exploitable when the readonly initialisation parameter of the Default servlet is set to false (enabling HTTP PUT). Default Tomcat installations are NOT vulnerable — exploitation requires a deliberate misconfiguration.
  • ·The vulnerability is Windows-specific — Apache Tomcat on non-Windows platforms is not affected by this particular file-upload vector.

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck8.1HIGH
cisa8.1HIGH
vendor_redhat8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.