Skip to main content

CVE-2017-12615

8.1
HIGHCVSS v3.1 Base Score
94.23%
HIGH RiskEPSS (100th percentile)
KEV

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Published: 9/19/2017
Modified: 4/21/2026
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Apache Tomcat on Windows Remote Code Execution Vulnerability

Vendor / Product:

Apache Tomcat

Required Action:

Apply updates per vendor instructions.

Due Date: 4/15/2022(OVERDUE)
Ransomware Campaign Use
Added to KEV:

3/25/2022

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2017-12615

Vulnerability Summary

CVSS v3 Score

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

6.8

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

94.23%HIGH Exploitation Risk
100th percentile

This vulnerability has a 94.23% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-434)

CVE-2025-13374CRITICAL 9.8

The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX action in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

1/24/2026
CVE-2026-1331CRITICAL 9.8

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

1/22/2026
CVE-2025-55251LOW 3.1

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.

1/19/2026
CVE-2025-14894CRITICAL 9.8

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.

1/16/2026
CVE-2022-50893CRITICAL 9.8

VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a malicious PHP file through the add_gallery_image.php endpoint to execute arbitrary code on the server.

1/13/2026

Similar SeverityHIGH