CVE-2017-12615
100Vexday Risk Score
Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.
ssvc Actcvss 8.1epss 100%
de la publicación al arma1 días
Publicada en NVD19 sept
1ª PoC+1d
CISA KEV+1648d
probabilidad de explotación
100%top 1% de las CVE
explotación observada
síCISA + VulnCheck
32 exploit(s) público(s)
Acción exigida por CISAplazo federal: 2022-04-15
Apply updates per vendor instructions.
Versiones
Afectadas
maven/org.apache.tomcat.embed:tomcat-embed-core >= 7.0.0, < 7.0.79
Corregidas en
maven/org.apache.tomcat.embed:tomcat-embed-core 7.0.79
Investigado y redactado con IA a partir del advisory del fabricante y análisis públicos, con las fuentes citadas. Verifica siempre la versión corregida en el advisory oficial antes de actuar.
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Apache Software Foundation · Apache TomcatPoCs públicas encontradas — 32
exploitdbwww.exploit-db.com/exploits/42953no verificadogithubgithub.com/lizhianyuguangming/TomcatScanPro★ 295githubgithub.com/tpt11fb/AttackTomcat★ 257githubgithub.com/breaktoprotect/CVE-2017-12615★ 112githubgithub.com/mefulton/cve-2017-12615★ 11githubgithub.com/xiaokp7/Tomcat_PUT_GUI_EXP★ 11githubgithub.com/zi0Black/POC-CVE-2017-12615-or-CVE-2017-12717★ 5githubgithub.com/1337g/CVE-2017-12615★ 3githubgithub.com/wsg00d/cve-2017-12615★ 2githubgithub.com/BeyondCy/CVE-2017-12615★ 1githubgithub.com/ianxtianxt/CVE-2017-12615★ 1githubgithub.com/w0x68y/CVE-2017-12615-EXP★ 1githubgithub.com/K3ysTr0K3R/CVE-2017-12615★ 0githubgithub.com/cyberharsh/Tomcat-CVE-2017-12615★ 0githubgithub.com/wudidwo/CVE-2017-12615-poc★ 0githubgithub.com/edyekomu/CVE-2017-12615-PoC★ 0githubgithub.com/Fa1c0n35/CVE-2017-12615★ 0githubgithub.com/netw0rk7/CVE-2017-12615-Home-Lab★ 0githubgithub.com/Shellkeys/CVE-2017-12615★ 0githubgithub.com/cved-sources/cve-2017-12615★ 0vulncheckvulncheck.com/xdb/8d7305eb7051no verificadovulncheckvulncheck.com/xdb/3e4c49fc05beno verificadovulncheckvulncheck.com/xdb/fbbcc0b93b98no verificadovulncheckvulncheck.com/xdb/990330be271fno verificadovulncheckvulncheck.com/xdb/1f8fb8c68353no verificadovulncheckvulncheck.com/xdb/70d9deaae392no verificadovulncheckvulncheck.com/xdb/814d0fdfdaf9no verificadovulncheckvulncheck.com/xdb/6889df0c7813no verificadocve_referencewww.exploit-db.com/exploits/42953/no verificadovulncheckvulncheck.com/xdb/08d6bfd35adcno verificadovulncheckvulncheck.com/xdb/5a1624c6df1bno verificadovulncheckvulncheck.com/xdb/b6f4790733eano verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://breaktoprotect.blogspot.com/2017/09/the-case-of-cve-2017-12615-tomcat-7-put.htmlhttps://access.redhat.com/errata/RHSA-2017:3080https://access.redhat.com/errata/RHSA-2017:3081https://access.redhat.com/errata/RHSA-2017:3113https://access.redhat.com/errata/RHSA-2017:3114https://access.redhat.com/errata/RHSA-2018:0465https://access.redhat.com/errata/RHSA-2018:0466https://github.com/breaktoprotect/CVE-2017-12615https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/8fcb1e2d5895413abcf266f011b9918ae03e0b7daceb118ffbf23f8c%40%3Cannounce.tomcat.apache.org%3E