CVE-2017-12615
HIGH(8.1)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 8.1 — Hoch
- EPSS 100% — sehr wahrscheinlich ausgenutzt
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
99.6%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
8.1
Technische Schwere
SecBoard-Einordnung
CVE-2017-12615 betrifft Apache Tomcat Versionen 7.0.0 bis 7.0.79 unter Windows, wenn HTTP PUT-Anfragen aktiviert sind. Angreifer können über eine speziell präparierte Anfrage eine JSP-Datei auf den Server hochladen. Diese hochgeladene Datei kann dann ausgeführt werden, was zur Ausführung von beliebigem Code auf dem Server führt.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Referenzen
- http://breaktoprotect.blogspot.com/2017/09/the-case-of-cve-2017-12615-tomcat-7-p...
- http://www.securityfocus.com/bid/100901
- http://www.securitytracker.com/id/1039392
- https://access.redhat.com/errata/RHSA-2017:3080
- https://access.redhat.com/errata/RHSA-2017:3081
- https://access.redhat.com/errata/RHSA-2017:3113
- https://access.redhat.com/errata/RHSA-2017:3114
- https://access.redhat.com/errata/RHSA-2018:0465
- https://access.redhat.com/errata/RHSA-2018:0466
- https://github.com/breaktoprotect/CVE-2017-12615