CVE-2017-12615: Apache Tomcat on Windows Remote Code Execution Vulnerability
High severity, CVSS 8.1. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 99.6% chance of exploitation in the next 30 days.
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Affected products
- Apache Tomcat: from 7.0.0, up to and including 7.0.79
- Netapp 7-Mode Transition Tool: affected versions not specified
- Netapp Oncommand Balance: affected versions not specified
- Netapp Oncommand Shift: affected versions not specified
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Eus: version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Eus Compute Node: version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux For IBM Z Systems: version 7.0_s390x only
- Red Hat Enterprise Linux For IBM Z Systems Eus: version 7.4_s390x only; version 7.5_s390x only; version 7.6_s390x only; version 7.7_s390x only
- Red Hat Enterprise Linux For Power Big Endian: version 7.0_ppc64 only
- Red Hat Enterprise Linux For Power Big Endian Eus: version 7.4_ppc64 only; version 7.5_ppc64 only; version 7.6_ppc64 only; version 7.7_ppc64 only
- Red Hat Enterprise Linux For Power Little Endian: version 7.0_ppc64le only
- Red Hat Enterprise Linux For Power Little Endian Eus: version 7.4_ppc64le only; version 7.5_ppc64le only; version 7.6_ppc64le only; version 7.7_ppc64le only
- Red Hat Enterprise Linux For Scientific Computing: version 7.0 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server For Power Little Endian Update Services For SAP Solutions: version 7.4_ppc64le only; version 7.6_ppc64le only; version 7.7_ppc64le only; version 9.2_ppc64le only
- Red Hat Enterprise Linux Server Tus: version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Update Services For SAP Solutions: version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
- Red Hat JBoss Enterprise Web Server: version 2.0.0 only; version 3.0.0 only
- Red Hat JBoss Enterprise Web Server Text-Only Advisories: affected versions not specified
Published 2017-09-19. Last modified 2026-08-06.