When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12615
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2022-03-25), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 8.1 retained for reference. Confidence: HIGH.
- 200 internet-exposed hosts are running an affected version right now
- Actively exploited in the wild (CISA-KEV)
- Linked to ransomware campaigns
A fix is available — apply it.
200 internet-exposed hosts are running an affected version of CVE-2017-12615 right now.
EchelonGraph is the only CVE feed that fuses live vulnerability intelligence with its own live internet-exposure radar — so you see not just that a CVE is exploited, but how much of the internet is exposed to it right now.
- CVSS v3
- 8.1
- EG Score
- 9.0(high)
- EG Risk
- 81(Attend)EG Risk 81/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity90% × 45%Exploitation100% × 40%Automatability0% × 15%Action: Remediate soon — notable exploitation risk. - EPSS PROB
- 100%
- EPSS %ILE
- 100%
- KEV
- ⚠ Exploited
Published
September 19, 2017
Last Modified
August 6, 2026
Advisory Details (10)
Auto-updated May 19, 2026GitHub - breaktoprotect/CVE-2017-12615: POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability. · GitHub
https://github.com/breaktoprotect/CVE-2017-12615Affected: Red Hat Enterprise Linux 7.
https://access.redhat.com/errata/RHSA-2017:3081Affected: Red Hat Enterprise Linux 6.
https://access.redhat.com/errata/RHSA-2017:3080Break To Protect: The Case of CVE-2017-12615 Tomcat 7 PUT vulnerability
http://breaktoprotect.blogspot.com/2017/09/the-case-of-cve-2017-12615-tomcat-7-put.htmlVendor Advisories for CVE-2017-12615(2)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(6)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | patch | 2018-03-07 | redhat |
| redhat | tomcat-vault-0:1.1.6-1.Final_redhat_1.1.ep7.el7 | 2018-03-07 | redhat |
| redhat | tomcat7 | 2017-11-02 | redhat |
| redhat | tomcat7-0:7.0.54-28_patch_05.ep6.el7 | 2017-11-02 | redhat |
| redhat | tomcat-0:7.0.76-3.el7_4 | 2017-10-30 | redhat |
| redhat | tomcat6-0:6.0.24-111.el6_9 | 2017-10-30 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
Maven(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-core | 7.0.0 ... 7.0.8 (54 versions) | 7.0.79 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(4)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
Data Freshness Timeline
(refreshed 46× in last 7d / 205× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 698 total refreshes for this CVE.
- 2026-09-08 09:51 UTCVendor advisory
- 2026-09-08 05:54 UTCVendor advisory
- 2026-09-08 01:59 UTCVendor advisory
- 2026-09-07 22:05 UTCVendor advisory
- 2026-09-07 18:11 UTCVendor advisory
- 2026-09-07 14:18 UTCVendor advisory
- 2026-09-07 10:23 UTCVendor advisory
- 2026-09-07 06:28 UTCVendor advisory
- 2026-09-07 02:31 UTCVendor advisory
- 2026-09-06 22:36 UTCVendor advisory
- 2026-09-06 18:41 UTCVendor advisory
- 2026-09-06 14:47 UTCVendor advisory
- 2026-09-06 10:53 UTCVendor advisory
- 2026-09-06 06:59 UTCVendor advisory
- 2026-09-06 03:05 UTCVendor advisory
- 2026-09-05 23:12 UTCVendor advisory
- 2026-09-05 19:18 UTCVendor advisory
- 2026-09-05 15:25 UTCEG score recompute
- 2026-09-05 15:25 UTCVendor advisory
- 2026-09-05 11:30 UTCVendor advisory
- 2026-09-05 07:36 UTCVendor advisory
- 2026-09-05 03:42 UTCVendor advisory
- 2026-09-04 23:48 UTCVendor advisory
- 2026-09-04 19:55 UTCVendor advisory
- 2026-09-04 17:38 UTCCISA KEV update
Show 75 moreShow fewer
- 2026-09-04 15:57 UTCVendor advisory
- 2026-09-04 12:04 UTCVendor advisory
- 2026-09-04 08:10 UTCVendor advisory
- 2026-09-04 04:14 UTCVendor advisory
- 2026-09-04 00:18 UTCVendor advisory
- 2026-09-03 20:23 UTCVendor advisory
- 2026-09-03 16:28 UTCVendor advisory
- 2026-09-03 12:34 UTCVendor advisory
- 2026-09-03 08:38 UTCVendor advisory
- 2026-09-03 04:44 UTCVendor advisory
- 2026-09-03 00:48 UTCVendor advisory
- 2026-09-02 20:53 UTCVendor advisory
- 2026-09-02 17:33 UTCCISA KEV update
- 2026-09-02 16:58 UTCVendor advisory
- 2026-09-02 12:59 UTCVendor advisory
- 2026-09-02 09:04 UTCVendor advisory
- 2026-09-02 05:11 UTCVendor advisory
- 2026-09-02 01:17 UTCVendor advisory
- 2026-09-01 21:21 UTCVendor advisory
- 2026-09-01 17:28 UTCVendor advisory
- 2026-09-01 13:33 UTCVendor advisory
- 2026-09-01 09:39 UTCVendor advisory
- 2026-09-01 05:43 UTCVendor advisory
- 2026-09-01 01:46 UTCVendor advisory
- 2026-08-31 21:51 UTCVendor advisory
- 2026-08-31 17:57 UTCVendor advisory
- 2026-08-31 14:19 UTCCISA KEV update
- 2026-08-31 14:01 UTCVendor advisory
- 2026-08-31 10:05 UTCVendor advisory
- 2026-08-31 06:09 UTCVendor advisory
- 2026-08-31 02:12 UTCVendor advisory
- 2026-08-30 22:19 UTCVendor advisory
- 2026-08-30 18:26 UTCVendor advisory
- 2026-08-30 14:32 UTCVendor advisory
- 2026-08-30 10:38 UTCVendor advisory
- 2026-08-30 06:44 UTCVendor advisory
- 2026-08-30 02:51 UTCVendor advisory
- 2026-08-29 22:57 UTCVendor advisory
- 2026-08-29 19:03 UTCVendor advisory
- 2026-08-29 15:08 UTCVendor advisory
- 2026-08-29 11:14 UTCVendor advisory
- 2026-08-29 07:19 UTCVendor advisory
- 2026-08-29 03:21 UTCVendor advisory
- 2026-08-28 23:27 UTCEG score recompute
- 2026-08-28 23:27 UTCVendor advisory
- 2026-08-28 21:36 UTCEPSS rescore
- 2026-08-28 19:32 UTCVendor advisory
- 2026-08-28 15:37 UTCVendor advisory
- 2026-08-28 11:34 UTCVendor advisory
- 2026-08-28 07:39 UTCVendor advisory
- 2026-08-28 03:39 UTCVendor advisory
- 2026-08-27 23:45 UTCVendor advisory
- 2026-08-27 19:51 UTCVendor advisory
- 2026-08-27 17:22 UTCCISA KEV update
- 2026-08-27 15:58 UTCVendor advisory
- 2026-08-27 12:04 UTCVendor advisory
- 2026-08-27 08:11 UTCVendor advisory
- 2026-08-27 04:16 UTCVendor advisory
- 2026-08-27 00:22 UTCVendor advisory
- 2026-08-26 20:28 UTCVendor advisory
- 2026-08-26 17:41 UTCCISA KEV update
- 2026-08-26 16:34 UTCEG score recompute
- 2026-08-26 16:34 UTCVendor advisory
- 2026-08-26 14:41 UTCEPSS rescore
- 2026-08-26 12:40 UTCVendor advisory
- 2026-08-26 08:46 UTCVendor advisory
- 2026-08-26 04:52 UTCVendor advisory
- 2026-08-26 00:58 UTCVendor advisory
- 2026-08-25 21:03 UTCVendor advisory
- 2026-08-25 17:09 UTCVendor advisory
- 2026-08-25 13:15 UTCVendor advisory
- 2026-08-25 09:21 UTCVendor advisory
- 2026-08-25 05:27 UTCVendor advisory
- 2026-08-25 01:33 UTCVendor advisory
- 2026-08-24 21:40 UTCVendor advisory
Publicly available exploits
(10 references)Working exploit code is in the public domain (8 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoClizhianyuguangming/TomcatScanProFirst seen Aug 29, 2024
tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含
Open source ↗ - GitHub PoCxiaokp7/Tomcat_PUT_GUI_EXPFirst seen Mar 10, 2023
Tomcat PUT方法任意文件写入(CVE-2017-12615)exp
Open source ↗ - GitHub PoCtpt11fb/AttackTomcatFirst seen Nov 13, 2022
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
Open source ↗ - GitHub PoC1337g/CVE-2017-12615First seen Dec 26, 2017
CVE-2017-12615 Tomcat RCE (TESTED)
Open source ↗ - GitHub PoCwsg00d/cve-2017-12615First seen Nov 1, 2017
tomcat-put-cve-2017-12615
Open source ↗ - GitHub PoCzi0Black/POC-CVE-2017-12615-or-CVE-2017-12717First seen Oct 6, 2017
CVE-2017-12617 and CVE-2017-12615 for tomcat server
Open source ↗ - GitHub PoCmefulton/cve-2017-12615First seen Sep 25, 2017
just a python script for cve-2017-12615
Open source ↗ - GitHub PoCbreaktoprotect/CVE-2017-12615First seen Sep 23, 2017
POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability.
Open source ↗ - Exploit-DBEDB-42953First seen Sep 20, 2017
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)
Open source ↗ - Nucleihttp/cves/2017/CVE-2017-12615.yamlFirst seen Jan 1, 2017
Apache Tomcat Servers - Remote Code Execution
Open source ↗
Frequently asked(6)
What is CVE-2017-12615?
When was CVE-2017-12615 disclosed?
Is CVE-2017-12615 actively exploited?
What is the CVSS score of CVE-2017-12615?
Which products are affected by CVE-2017-12615?
How do I remediate CVE-2017-12615?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2017-12615
Is Your Infrastructure Affected by CVE-2017-12615?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.