Back

HIGH KEV Used in ransomware campaigns

tomcat: Remote Code Execution via JSP Upload

Published Sep 19, 2017 ·Due Apr 15, 2022

Description

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Affected products

Remediation

Red Hat statement

This flaw affects Tomcat on Red Hat Enterprise Linux only when a specific context is configured with readonly=false. The default configuration has a readonly context, so it is not affected.

Red Hat mitigation

Ensure that readonly is set to true (the default) for the DefaultServlet, WebDAV servlet or application context. Block HTTP methods that permit resource modification for untrusted users.

Metrics

References (33)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 19, 2017
Updated Aug 6, 2026
Reserved Aug 7, 2017
CISA Vulnrichment
Updated Feb 6, 2025
NVD
Status Analyzed
Modified Aug 6, 2026
Red Hat
Severity Important
Public date Sep 19, 2017
GHSA-PJFR-QF3P-3Q25