CVE-2017-12615
Apache Tomcat on Windows Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.61% probability · 100th percentile
- CISA KEV
- Listed 25 March 2022 · due 15 April 2022 · used in ransomware campaigns
- Weakness
- CWE-434
- Affected
- apache/tomcat · netapp/7-mode transition tool · netapp/oncommand balance · netapp/oncommand shift · redhat/enterprise linux server update services for sap solutions · redhat/jboss enterprise web server · redhat/jboss enterprise web server text-only advisories · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux eus compute node · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for ibm z systems eus · redhat/enterprise linux for power big endian · redhat/enterprise linux for power big endian eus · redhat/enterprise linux for power little endian · redhat/enterprise linux for power little endian eus · redhat/enterprise linux for scientific computing · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server for power little endian update services for sap solutions · +2 more
- Source
- security@apache.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2017-12615
References
- http://breaktoprotect.blogspot.com/2017/09/the-case-of-cve-2017-12615-tomcat-7-put.htmlExploit
- http://www.securityfocus.com/bid/100901Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039392Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:3080Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3081Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3113Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3114Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0465Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0466Third Party Advisory
- https://github.com/breaktoprotect/CVE-2017-12615Exploit, Third Party Advisory
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/8fcb1e2d5895413abcf266f011b9918ae03e0b7daceb118ffbf23f8c%40%3Cannounce.tomcat.apache.org%3EIssue Tracking, Mailing List
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3EMailing List
- https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
- https://security.netapp.com/advisory/ntap-20171018-0001/Third Party Advisory
- https://www.exploit-db.com/exploits/42953/Third Party Advisory, VDB Entry
- https://www.synology.com/support/security/Synology_SA_17_54_TomcatThird Party Advisory
- http://breaktoprotect.blogspot.com/2017/09/the-case-of-cve-2017-12615-tomcat-7-put.htmlExploit
- http://www.securityfocus.com/bid/100901Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039392Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:3080Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3081Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3113Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3114Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0465Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0466Third Party Advisory
- https://github.com/breaktoprotect/CVE-2017-12615Exploit, Third Party Advisory
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3EMailing List, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.