← Vulnerability feed

Vulnerability record · CVE-2017-12615 · published 19 September 2017

CVE-2017-12615: Apache Tomcat on Windows unrestricted JSP upload via HTTP PUT

Apache · Tomcat

Apache Tomcat 7.0.0 through 7.0.79 on Windows with HTTP PUT enabled (for example, Default servlet readonly set to false) allows an attacker to upload a JSP file through a specially crafted request. The uploaded JSP can then be requested and executed by the server, giving remote code execution.

8.1 CVSS 3.1 High CISA KEV since 25 Mar 2022 Known ransomware use EPSS 100% · top 0.1% CWE-434 · Unrestricted file upload
8.1CVSS 3.1 base score, v2 6.8
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
22Affected product versions listed by NVD
39References, 4 tagged exploit
6 Aug 2026Last modified by NVD

Description

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has a near-maximum EPSS score, and yields unauthenticated remote code execution.

What it is

Apache Tomcat 7.0.0 through 7.0.79 on Windows with HTTP PUT enabled (for example, Default servlet readonly set to false) allows an attacker to upload a JSP file through a specially crafted request. The uploaded JSP can then be requested and executed by the server, giving remote code execution.

Impact

An unauthenticated attacker can place and execute arbitrary Java server-side code, leading to full compromise of the Tomcat process and potentially the host.

Attack surface

Reached over the network via HTTP PUT requests to the Tomcat connector; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N). The flaw only applies when PUT is enabled and the instance runs on Windows.

Exploitation

CISA KEV lists it as actively exploited with known ransomware campaign use, and EPSS is 0.99607 (99.9th percentile); public exploit references exist.

What to do

  • Upgrade Apache Tomcat to a fixed release (7.0.80 or later) or apply the vendor patch referenced in the Apache mailing list advisories.
  • Disable HTTP PUT on the Default servlet by keeping readonly set to true unless explicitly required.
  • If PUT must remain enabled, restrict write access to trusted networks and enforce authentication and authorization on the connector.
  • Apply Red Hat, NetApp and other vendor errata for bundled Tomcat components.
  • Monitor and remove any unexpected JSP files written to web application directories.

Detection

  • Alert on HTTP PUT requests to Tomcat that create .jsp or .jspx files, especially with trailing characters or alternate extensions.
  • Monitor web directories for newly created JSP files outside of normal deployment processes.
  • Review Tomcat access logs for PUT requests followed by GET requests to the same uploaded path.
  • Watch for child processes or outbound connections spawned by the Tomcat service after JSP access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-12615 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Apache Tomcat on Windows Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

22 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://breaktoprotect.blogspot.com/2017/09/the-case-of-cve-2017-12615-tomcat-7-put.html Exploit
http://www.securityfocus.com/bid/100901 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039392 Broken LinkThird Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2017:3080 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3081 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3113 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3114 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0465 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0466 Third Party Advisory
https://github.com/breaktoprotect/CVE-2017-12615 ExploitThird Party Advisory
https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org Mailing ListPatch
https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org Mailing ListPatch
https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org Mailing ListPatch
https://lists.apache.org/thread.html/8fcb1e2d5895413abcf266f011b9918ae03e0b7daceb118ffbf23f8c%40%3Cannounce.tomcat.apach Issue TrackingMailing List
https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org% Mailing List
https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.or Mailing ListPatch
https://security.netapp.com/advisory/ntap-20171018-0001/ Third Party Advisory
https://www.exploit-db.com/exploits/42953/ Third Party AdvisoryVDB Entry
https://www.synology.com/support/security/Synology_SA_17_54_Tomcat Third Party Advisory
http://breaktoprotect.blogspot.com/2017/09/the-case-of-cve-2017-12615-tomcat-7-put.html Exploit
http://www.securityfocus.com/bid/100901 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039392 Broken LinkThird Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2017:3080 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3081 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3113 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:3114 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0465 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0466 Third Party Advisory
https://github.com/breaktoprotect/CVE-2017-12615 ExploitThird Party Advisory
https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org Mailing ListPatch
https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org Mailing ListPatch
https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org Mailing ListPatch
https://lists.apache.org/thread.html/8fcb1e2d5895413abcf266f011b9918ae03e0b7daceb118ffbf23f8c%40%3Cannounce.tomcat.apach Issue TrackingMailing List
https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org% Mailing List
https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.or Mailing ListPatch
https://security.netapp.com/advisory/ntap-20171018-0001/ Third Party Advisory
https://www.exploit-db.com/exploits/42953/ Third Party AdvisoryVDB Entry
https://www.synology.com/support/security/Synology_SA_17_54_Tomcat Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12615 US Government Resource

Track CVE-2017-12615 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2019-5544OpenSLP heap out-of-bounds write in VMware ESXi and Horizon DaaSOpenSLP as shipped in VMware ESXi and Horizon DaaS contains a heap overwrite (out-of-bounds write) flaw. VMware rates it Critical with a maximum CVSS…KEVEPSS 97%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed9.8CVE-2017-5638Apache Struts 2 Jakarta Multipart parser remote code executionThe Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type,…KEVEPSS 100%analysed9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed

Source: NIST National Vulnerability Database (record CVE-2017-12615), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.