Back

HIGH KEV

tomcat: Remote Code Execution bypass for CVE-2017-12615

Published Oct 3, 2017 ·Due Apr 15, 2022

Description

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Affected products

Remediation

Red Hat statement

This flaw affects Tomcat on Red Hat Enterprise Linux only when a specific context is configured with readonly=false. The default configuration has a readonly context, so it is not affected.

Red Hat mitigation

Ensure that readonly is set to true (the default) for the DefaultServlet, WebDAV servlet or application context. Block HTTP methods that permit resource modification for untrusted users.

Metrics

References (90)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Oct 3, 2017
Updated Oct 21, 2025
Reserved Aug 7, 2017
CISA Vulnrichment
Updated Feb 4, 2025
NVD
Status Analyzed
Modified Aug 25, 2026
Red Hat
Severity Important
Public date Sep 21, 2017
GHSA-XJGH-84HX-56C5