Skip to main content

CVE detail

CVE-2017-12615

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVSS 8.1 · HighBuzz score 63.4KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 63.4

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 22.0 · diversity 11.5 · KEV 25.0 · OTX 0.0 · PoC 5.0
Mention score
22.0
8 evidence mentions in the snapshot
Diversity score
11.5
3 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
5.0
1 repos · best confidence 0.99
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
8 source links · newest first
  • 10th June – Threat Intelligence BulletinCheck Point Research

    For the latest discoveries in cyber research for the week of 10th June 2019, please download our Threat Intelligence Bulletin TOP ATTACKS AND BREACHES American Medical Collection Agency (AMCA) has suffered a major data breach exposing personal and payment information of some ten million patients. The information included names, date of birth, address, […]

    vendorresearch.checkpoint.comJun 16, 2019, 8:09 AM
  • A new piece of malware appeared in the threat landscape, dubbed BlackSquid it targets web servers with several exploits to deliver cryptocurrency miners. Security experts at Trend Micro have discovered a new Monero cryptomining miner, dubbed BlackSquid, that is targeting web servers, network drives, and removable drives. The new piece of malware leverages many exploits […]

    newssecurityaffairs.comJun 5, 2019, 7:19 AM
  • A variant of the Satan ransomware recently observed includes exploits to its arsenal and targets machines leveraging additional flaws. Experts at FortiGuard Labs have discovered a new variant of the Satan ransomware that includes new exploits to its portfolio and leverages additional vulnerabilities to infect as many machines as possible. The Satan ransomware first appeared […]

    newssecurityaffairs.comMay 22, 2019, 6:36 AM
  • A recently observed Satan ransomware variant has added exploits to its portfolio and is looking to compromise more machines by targeting additional vulnerabilities.

    newswww.securityweek.comMay 21, 2019, 4:03 PM
  • A new cyptojacking campaign targeting enterprises in Asia is leveraging the National Security Agency-linked DoublePulsar backdoor and the EternalBlue exploit for network spreading, Symantec reveals.

    newswww.securityweek.comApr 26, 2019, 2:14 PM
  • Security experts uncovered a new cryptojacking campaign tracked as Beapy that leverages the NSA’s DoublePulsar backdoor and the EternalBlue exploit. Security experts at Symantec have uncovered a new cryptojacking campaign tracked as Beapy that leverages the NSA’s DoublePulsar backdoor and the EternalBlue exploit to spread a cryptocurrency malware on enterprise networks in Asia. “Beapy is […]

    newssecurityaffairs.comApr 26, 2019, 2:05 PM
  • Several security vulnerabilities have been patched in recent weeks in Apache Tomcat, including the CVE-2017-12617 Code Execution vulnerability. Several security vulnerabilities have been patched in recent weeks in Apache Tomcat. The list of fixed flaws recently addressed also included code execution vulnerabilities. Apache Tomcat is the most widely used web application server, with over one million downloads […]

    newssecurityaffairs.comOct 5, 2017, 7:30 AM
  • Several vulnerabilities, including ones that allow remote attackers to execute arbitrary code, have been patched in recent weeks in Apache Tomcat.

    newswww.securityweek.comOct 4, 2017, 6:58 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 0 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence