Vulnerability record · CVE-2017-12615 · published 19 September 2017
CVE-2017-12615: Apache Tomcat on Windows unrestricted JSP upload via HTTP PUT
Apache · Tomcat
Apache Tomcat 7.0.0 through 7.0.79 on Windows with HTTP PUT enabled (for example, Default servlet readonly set to false) allows an attacker to upload a JSP file through a specially crafted request. The uploaded JSP can then be requested and executed by the server, giving remote code execution.
Description
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has a near-maximum EPSS score, and yields unauthenticated remote code execution.
What it is
Apache Tomcat 7.0.0 through 7.0.79 on Windows with HTTP PUT enabled (for example, Default servlet readonly set to false) allows an attacker to upload a JSP file through a specially crafted request. The uploaded JSP can then be requested and executed by the server, giving remote code execution.
Impact
An unauthenticated attacker can place and execute arbitrary Java server-side code, leading to full compromise of the Tomcat process and potentially the host.
Attack surface
Reached over the network via HTTP PUT requests to the Tomcat connector; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N). The flaw only applies when PUT is enabled and the instance runs on Windows.
Exploitation
CISA KEV lists it as actively exploited with known ransomware campaign use, and EPSS is 0.99607 (99.9th percentile); public exploit references exist.
What to do
- Upgrade Apache Tomcat to a fixed release (7.0.80 or later) or apply the vendor patch referenced in the Apache mailing list advisories.
- Disable HTTP PUT on the Default servlet by keeping readonly set to true unless explicitly required.
- If PUT must remain enabled, restrict write access to trusted networks and enforce authentication and authorization on the connector.
- Apply Red Hat, NetApp and other vendor errata for bundled Tomcat components.
- Monitor and remove any unexpected JSP files written to web application directories.
Detection
- Alert on HTTP PUT requests to Tomcat that create .jsp or .jspx files, especially with trailing characters or alternate extensions.
- Monitor web directories for newly created JSP files outside of normal deployment processes.
- Review Tomcat access logs for PUT requests followed by GET requests to the same uploaded path.
- Watch for child processes or outbound connections spawned by the Tomcat service after JSP access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-12615 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Apache Tomcat on Windows Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
22 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-12615 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12615), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.