When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12615
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2022-03-25), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 8.1 retained for reference. Confidence: HIGH.
- 150 internet-exposed hosts are running an affected version right now
- Actively exploited in the wild (CISA-KEV)
- Linked to ransomware campaigns
A fix is available — apply it.
150 internet-exposed hosts are running an affected version of CVE-2017-12615 right now.
EchelonGraph is the only CVE feed that fuses live vulnerability intelligence with its own live internet-exposure radar — so you see not just that a CVE is exploited, but how much of the internet is exposed to it right now.
- CVSS v3
- 8.1
- EG Score
- 9.0(high)
- EG Risk
- 81(Attend)EG Risk 81/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity90% × 45%Exploitation100% × 40%Automatability0% × 15%Action: Remediate soon — notable exploitation risk. - EPSS PROB
- 100%
- EPSS %ILE
- 100%
- KEV
- ⚠ Exploited
Published
September 19, 2017
Last Modified
August 6, 2026
Advisory Details (10)
Auto-updated May 19, 2026GitHub - breaktoprotect/CVE-2017-12615: POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability. · GitHub
https://github.com/breaktoprotect/CVE-2017-12615Affected: Red Hat Enterprise Linux 7.
https://access.redhat.com/errata/RHSA-2017:3081Affected: Red Hat Enterprise Linux 6.
https://access.redhat.com/errata/RHSA-2017:3080Break To Protect: The Case of CVE-2017-12615 Tomcat 7 PUT vulnerability
http://breaktoprotect.blogspot.com/2017/09/the-case-of-cve-2017-12615-tomcat-7-put.htmlVendor Advisories for CVE-2017-12615(2)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(6)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | patch | 2018-03-07 | redhat |
| redhat | tomcat-vault-0:1.1.6-1.Final_redhat_1.1.ep7.el7 | 2018-03-07 | redhat |
| redhat | tomcat7 | 2017-11-02 | redhat |
| redhat | tomcat7-0:7.0.54-28_patch_05.ep6.el7 | 2017-11-02 | redhat |
| redhat | tomcat-0:7.0.76-3.el7_4 | 2017-10-30 | redhat |
| redhat | tomcat6-0:6.0.24-111.el6_9 | 2017-10-30 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
Maven(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-core | 7.0.0 ... 7.0.8 (54 versions) | 7.0.79 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(4)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
Data Freshness Timeline
(refreshed 49× in last 7d / 210× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 774 total refreshes for this CVE.
- 2026-09-19 04:34 UTCVendor advisory
- 2026-09-19 00:39 UTCVendor advisory
- 2026-09-18 20:46 UTCVendor advisory
- 2026-09-18 19:20 UTCCISA KEV update
- 2026-09-18 16:53 UTCVendor advisory
- 2026-09-18 14:15 UTCCISA KEV update
- 2026-09-18 12:59 UTCVendor advisory
- 2026-09-18 09:05 UTCVendor advisory
- 2026-09-18 05:11 UTCVendor advisory
- 2026-09-18 01:17 UTCVendor advisory
- 2026-09-17 21:24 UTCEG score recompute
- 2026-09-17 21:24 UTCVendor advisory
- 2026-09-17 19:22 UTCEPSS rescore
- 2026-09-17 17:30 UTCVendor advisory
- 2026-09-17 12:52 UTCVendor advisory
- 2026-09-17 08:56 UTCVendor advisory
- 2026-09-17 05:03 UTCVendor advisory
- 2026-09-17 01:09 UTCVendor advisory
- 2026-09-16 21:15 UTCVendor advisory
- 2026-09-16 17:21 UTCVendor advisory
- 2026-09-16 14:10 UTCCISA KEV update
- 2026-09-16 13:25 UTCVendor advisory
- 2026-09-16 09:29 UTCVendor advisory
- 2026-09-16 05:35 UTCVendor advisory
- 2026-09-16 01:42 UTCVendor advisory
Show 75 moreShow fewer
- 2026-09-15 21:48 UTCVendor advisory
- 2026-09-15 17:54 UTCVendor advisory
- 2026-09-15 14:00 UTCVendor advisory
- 2026-09-15 10:07 UTCVendor advisory
- 2026-09-15 06:13 UTCVendor advisory
- 2026-09-15 02:18 UTCVendor advisory
- 2026-09-14 22:23 UTCVendor advisory
- 2026-09-14 19:24 UTCCISA KEV update
- 2026-09-14 18:27 UTCVendor advisory
- 2026-09-14 14:33 UTCVendor advisory
- 2026-09-14 10:39 UTCVendor advisory
- 2026-09-14 06:45 UTCVendor advisory
- 2026-09-14 02:51 UTCVendor advisory
- 2026-09-13 22:57 UTCVendor advisory
- 2026-09-13 19:04 UTCVendor advisory
- 2026-09-13 15:11 UTCVendor advisory
- 2026-09-13 11:17 UTCVendor advisory
- 2026-09-13 07:23 UTCVendor advisory
- 2026-09-13 03:30 UTCVendor advisory
- 2026-09-12 23:36 UTCVendor advisory
- 2026-09-12 19:42 UTCVendor advisory
- 2026-09-12 15:48 UTCVendor advisory
- 2026-09-12 11:55 UTCVendor advisory
- 2026-09-12 08:01 UTCVendor advisory
- 2026-09-12 04:07 UTCVendor advisory
- 2026-09-12 00:14 UTCVendor advisory
- 2026-09-11 20:20 UTCVendor advisory
- 2026-09-11 18:49 UTCCISA KEV update
- 2026-09-11 16:26 UTCVendor advisory
- 2026-09-11 12:32 UTCVendor advisory
- 2026-09-11 08:36 UTCVendor advisory
- 2026-09-11 04:42 UTCVendor advisory
- 2026-09-11 00:48 UTCVendor advisory
- 2026-09-10 20:55 UTCVendor advisory
- 2026-09-10 19:28 UTCCISA KEV update
- 2026-09-10 17:00 UTCVendor advisory
- 2026-09-10 13:06 UTCVendor advisory
- 2026-09-10 09:12 UTCVendor advisory
- 2026-09-10 05:18 UTCVendor advisory
- 2026-09-10 01:24 UTCVendor advisory
- 2026-09-09 21:27 UTCVendor advisory
- 2026-09-09 19:08 UTCCISA KEV update
- 2026-09-09 17:32 UTCVendor advisory
- 2026-09-09 13:38 UTCVendor advisory
- 2026-09-09 09:45 UTCVendor advisory
- 2026-09-09 05:52 UTCVendor advisory
- 2026-09-09 01:58 UTCVendor advisory
- 2026-09-08 22:05 UTCVendor advisory
- 2026-09-08 18:54 UTCCISA KEV update
- 2026-09-08 18:11 UTCVendor advisory
- 2026-09-08 13:47 UTCVendor advisory
- 2026-09-08 09:51 UTCVendor advisory
- 2026-09-08 05:54 UTCVendor advisory
- 2026-09-08 01:59 UTCVendor advisory
- 2026-09-07 22:05 UTCVendor advisory
- 2026-09-07 18:11 UTCVendor advisory
- 2026-09-07 14:18 UTCVendor advisory
- 2026-09-07 10:23 UTCVendor advisory
- 2026-09-07 06:28 UTCVendor advisory
- 2026-09-07 02:31 UTCVendor advisory
- 2026-09-06 22:36 UTCVendor advisory
- 2026-09-06 18:41 UTCVendor advisory
- 2026-09-06 14:47 UTCVendor advisory
- 2026-09-06 10:53 UTCVendor advisory
- 2026-09-06 06:59 UTCVendor advisory
- 2026-09-06 03:05 UTCVendor advisory
- 2026-09-05 23:12 UTCVendor advisory
- 2026-09-05 19:18 UTCVendor advisory
- 2026-09-05 15:25 UTCEG score recompute
- 2026-09-05 15:25 UTCVendor advisory
- 2026-09-05 11:30 UTCVendor advisory
- 2026-09-05 07:36 UTCVendor advisory
- 2026-09-05 03:42 UTCVendor advisory
- 2026-09-04 23:48 UTCVendor advisory
- 2026-09-04 19:55 UTCVendor advisory
Publicly available exploits
(10 references)Working exploit code is in the public domain (8 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoClizhianyuguangming/TomcatScanProFirst seen Aug 29, 2024
tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含
Open source ↗ - GitHub PoCxiaokp7/Tomcat_PUT_GUI_EXPFirst seen Mar 10, 2023
Tomcat PUT方法任意文件写入(CVE-2017-12615)exp
Open source ↗ - GitHub PoCtpt11fb/AttackTomcatFirst seen Nov 13, 2022
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
Open source ↗ - GitHub PoC1337g/CVE-2017-12615First seen Dec 26, 2017
CVE-2017-12615 Tomcat RCE (TESTED)
Open source ↗ - GitHub PoCwsg00d/cve-2017-12615First seen Nov 1, 2017
tomcat-put-cve-2017-12615
Open source ↗ - GitHub PoCzi0Black/POC-CVE-2017-12615-or-CVE-2017-12717First seen Oct 6, 2017
CVE-2017-12617 and CVE-2017-12615 for tomcat server
Open source ↗ - GitHub PoCmefulton/cve-2017-12615First seen Sep 25, 2017
just a python script for cve-2017-12615
Open source ↗ - GitHub PoCbreaktoprotect/CVE-2017-12615First seen Sep 23, 2017
POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability.
Open source ↗ - Exploit-DBEDB-42953First seen Sep 20, 2017
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)
Open source ↗ - Nucleihttp/cves/2017/CVE-2017-12615.yamlFirst seen Jan 1, 2017
Apache Tomcat Servers - Remote Code Execution
Open source ↗
Related CVEs(same vendor + same CWE)
Same vendor
10 shownredhat
- CVE-2001-0825EG 10.0HIGH
- CVE-2001-1009EG 10.0EPSS p93HIGH
- CVE-2001-0554EG 10.0EPSS p99HIGH
- CVE-2001-1162EG 10.0EPSS p96HIGH
- CVE-2001-0414EG 10.0EPSS p100HIGH
- CVE-2001-0191EG 10.0EPSS p92HIGH
- CVE-2001-0301EG 10.0EPSS p91HIGH
- CVE-2001-0197EG 10.0EPSS p96HIGH
- CVE-2001-0233EG 10.0EPSS p96HIGH
- CVE-2001-0010EG 10.0EPSS p98HIGH
Same CWE
10 shownCWE-434
Frequently asked(6)
What is CVE-2017-12615?
When was CVE-2017-12615 disclosed?
Is CVE-2017-12615 actively exploited?
What is the CVSS score of CVE-2017-12615?
Which products are affected by CVE-2017-12615?
How do I remediate CVE-2017-12615?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2017-12615
Is Your Infrastructure Affected by CVE-2017-12615?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.