SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2017-12615

Apache Tomcat on Windows Remote Code Execution Vulnerability

KEVHIGH 8.1EPSS 99.6%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.61% probability · 100th percentile
CISA KEV
Listed 25 March 2022 · due 15 April 2022 · used in ransomware campaigns
Weakness
CWE-434
Affected
apache/tomcat · netapp/7-mode transition tool · netapp/oncommand balance · netapp/oncommand shift · redhat/enterprise linux server update services for sap solutions · redhat/jboss enterprise web server · redhat/jboss enterprise web server text-only advisories · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux eus compute node · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for ibm z systems eus · redhat/enterprise linux for power big endian · redhat/enterprise linux for power big endian eus · redhat/enterprise linux for power little endian · redhat/enterprise linux for power little endian eus · redhat/enterprise linux for scientific computing · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server for power little endian update services for sap solutions · +2 more
Source
security@apache.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2017-12615

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.