CVE-2017-12615High· 8.1▾ Abyssal⚠ Exploited in the wildPoC availableWhen running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted requ…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 44.6 · likelihood 19.9 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Apr 15, 2022
Last analysed / modified upstream
100%
Exploit-DB · 18 GitHub repos · Nuclei ×1 (last check)
Added to the CISA catalog on Mar 25, 2022. Federal remediation due Apr 15, 2022. View catalog ↗
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
tomcat >= 7.0.0, <= 7.0.797-mode_transition_tooloncommand_balanceoncommand_shiftenterprise_linux_server_update_services_for_sap_solutions = 7.4enterprise_linux_server_update_services_for_sap_solutions = 7.6enterprise_linux_server_update_services_for_sap_solutions = 7.7jboss_enterprise_web_server = 2.0.0jboss_enterprise_web_server = 3.0.0jboss_enterprise_web_server_text-only_advisoriesenterprise_linux_desktop = 6.0enterprise_linux_desktop = 7.0enterprise_linux_eus = 7.4enterprise_linux_eus = 7.5enterprise_linux_eus = 7.6enterprise_linux_eus = 7.7enterprise_linux_eus_compute_node = 7.4enterprise_linux_eus_compute_node = 7.5enterprise_linux_eus_compute_node = 7.6enterprise_linux_eus_compute_node = 7.7enterprise_linux_for_ibm_z_systems = 7.0_s390xenterprise_linux_for_ibm_z_systems_eus = 7.4_s390xenterprise_linux_for_ibm_z_systems_eus = 7.5_s390xenterprise_linux_for_ibm_z_systems_eus = 7.6_s390xenterprise_linux_for_ibm_z_systems_eus = 7.7_s390xenterprise_linux_for_power_big_endian = 7.0_ppc64enterprise_linux_for_power_big_endian_eus = 7.4_ppc64enterprise_linux_for_power_big_endian_eus = 7.5_ppc64enterprise_linux_for_power_big_endian_eus = 7.6_ppc64enterprise_linux_for_power_big_endian_eus = 7.7_ppc64enterprise_linux_for_power_little_endian = 7.0_ppc64leenterprise_linux_for_power_little_endian_eus = 7.4_ppc64leenterprise_linux_for_power_little_endian_eus = 7.5_ppc64leenterprise_linux_for_power_little_endian_eus = 7.6_ppc64leenterprise_linux_for_power_little_endian_eus = 7.7_ppc64leenterprise_linux_for_scientific_computing = 7.0enterprise_linux_server = 6.0enterprise_linux_server = 7.0enterprise_linux_server_aus = 7.4enterprise_linux_server_aus = 7.6enterprise_linux_server_aus = 7.7enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 7.4_ppc64leenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 7.6_ppc64leenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 7.7_ppc64leenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.2_ppc64leenterprise_linux_server_tus = 7.4enterprise_linux_server_tus = 7.6enterprise_linux_server_tus = 7.7enterprise_linux_workstation = 6.0enterprise_linux_workstation = 7.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2017-12617High· 8.1When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g
CVE-2016-8735Critical· 9.8Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports
CVE-2024-50623Critical· 9.8In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
CVE-2026-34486High· 7.5Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …
CVE-2017-11357Critical· 9.8Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
CVE-2020-13935High· 7.5The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104