CVE-2017-12615
גבוהה 8.1 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apache Tomcat on Windows Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
מדדים
- CVSS 3.1
-
8.1 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-434
מוצרים מושפעים
apache: tomcat; microsoft: windows; netapp: 7-mode transition tool; netapp: oncommand balance; netapp: oncommand shift; redhat: enterprise linux server update services for sap solutions; redhat: jboss enterprise web server; redhat: jboss enterprise web server text-only advisories; redhat: enterprise linux desktop; redhat: enterprise linux eus; redhat: enterprise linux eus compute node; redhat: enterprise linux for ibm z systems; redhat: enterprise linux for ibm z systems eus; redhat: enterprise linux for power big endian; redhat: enterprise linux for power big endian eus
קישורים
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e… Mailing ListPatch
- https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04… Mailing ListPatch
- https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d… Mailing ListPatch
- https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a1485… Mailing ListPatch
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e… Mailing ListPatch
- https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04… Mailing ListPatch
- https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d… Mailing ListPatch
- https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a1485… Mailing ListPatch
- http://breaktoprotect.blogspot.com/2017/09/the-case-of-cve-2017-12615-tomcat-7… Exploit
- https://github.com/breaktoprotect/CVE-2017-12615 ExploitThird Party Advisory