Learn about CVE-2017-12615 affecting Apache Tomcat 7.0.0 to 7.0.79 on Windows, allowing remote code execution via JSP upload. Find mitigation steps and necessary updates here.
Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled allowed the upload of a JSP file, leading to remote code execution.
Understanding CVE-2017-12615
Apache Tomcat vulnerability enabling remote code execution via JSP upload.
What is CVE-2017-12615?
When Apache Tomcat 7.0.0 to 7.0.79 is used on a Windows system with HTTP PUTs enabled, it allows the upload of a JSP file to the server through a manipulated request. This file can then be accessed and executed by the server, potentially leading to remote code execution.
The Impact of CVE-2017-12615
The vulnerability allows attackers to upload malicious JSP files to the server, leading to unauthorized code execution and potential compromise of the system.
Technical Details of CVE-2017-12615
Apache Tomcat vulnerability details.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting systems from CVE-2017-12615.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates