When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CVE-2017-12615
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2022-03-25), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 8.1 retained for reference. Confidence: HIGH.
- 47 internet-exposed hosts are running an affected version right now
- Actively exploited in the wild (CISA-KEV)
- Linked to ransomware campaigns
A fix is available — apply it.
47 internet-exposed hosts are running an affected version of CVE-2017-12615 right now.
EchelonGraph is the only CVE feed that fuses live vulnerability intelligence with its own live internet-exposure radar — so you see not just that a CVE is exploited, but how much of the internet is exposed to it right now.
- CVSS v3
- 8.1
- EG Score
- 9.0(high)
- EG Risk
- 81(Attend)EG Risk 81/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity90% × 45%Exploitation100% × 40%Automatability0% × 15%Action: Remediate soon — notable exploitation risk. - EPSS
- 99.9%
- KEV
- ⚠ Exploited
Published
September 19, 2017
Last Modified
April 21, 2026
Advisory Details (10)
Auto-updated May 19, 2026GitHub - breaktoprotect/CVE-2017-12615: POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability. · GitHub
https://github.com/breaktoprotect/CVE-2017-12615Affected: Red Hat Enterprise Linux 7.
https://access.redhat.com/errata/RHSA-2017:3081Affected: Red Hat Enterprise Linux 6.
https://access.redhat.com/errata/RHSA-2017:3080Break To Protect: The Case of CVE-2017-12615 Tomcat 7 PUT vulnerability
http://breaktoprotect.blogspot.com/2017/09/the-case-of-cve-2017-12615-tomcat-7-put.htmlVendor Advisories for CVE-2017-12615(2)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(6)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | patch | 2018-03-07 | redhat |
| redhat | tomcat-vault-0:1.1.6-1.Final_redhat_1.1.ep7.el7 | 2018-03-07 | redhat |
| redhat | tomcat7 | 2017-11-02 | redhat |
| redhat | tomcat7-0:7.0.54-28_patch_05.ep6.el7 | 2017-11-02 | redhat |
| redhat | tomcat6-0:6.0.24-111.el6_9 | 2017-10-30 | redhat |
| redhat | tomcat-0:7.0.76-3.el7_4 | 2017-10-30 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
Maven(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-core | 7.0.0 ... 7.0.8 (54 versions) | 7.0.79 | — |
Additional Vendor Advisories
(4)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
Data Freshness Timeline
(refreshed 53× in last 7d / 208× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 390 total refreshes for this CVE.
- 2026-07-23 01:26 UTCEG score recompute
- 2026-07-22 22:05 UTCEG score recompute
- 2026-07-22 20:49 UTCVendor advisory
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 16:53 UTCVendor advisory
- 2026-07-22 12:56 UTCVendor advisory
- 2026-07-22 09:03 UTCVendor advisory
- 2026-07-22 05:08 UTCVendor advisory
- 2026-07-22 00:45 UTCVendor advisory
- 2026-07-21 20:10 UTCVendor advisory
- 2026-07-21 16:16 UTCEG score recompute
- 2026-07-21 16:16 UTCVendor advisory
- 2026-07-21 15:21 UTCEPSS rescore
- 2026-07-21 15:21 UTCEPSS rescore
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-21 12:22 UTCVendor advisory
- 2026-07-21 08:29 UTCVendor advisory
- 2026-07-21 04:35 UTCVendor advisory
- 2026-07-21 00:41 UTCVendor advisory
- 2026-07-20 20:47 UTCVendor advisory
- 2026-07-20 16:54 UTCVendor advisory
- 2026-07-20 13:00 UTCVendor advisory
- 2026-07-20 09:07 UTCVendor advisory
- 2026-07-20 05:11 UTCVendor advisory
- 2026-07-20 01:17 UTCVendor advisory
Show 75 moreShow fewer
- 2026-07-19 21:23 UTCVendor advisory
- 2026-07-19 17:29 UTCEG score recompute
- 2026-07-19 17:29 UTCVendor advisory
- 2026-07-19 14:28 UTCEPSS rescore
- 2026-07-19 14:28 UTCEPSS rescore
- 2026-07-19 13:35 UTCVendor advisory
- 2026-07-19 09:37 UTCVendor advisory
- 2026-07-19 05:43 UTCVendor advisory
- 2026-07-19 01:49 UTCVendor advisory
- 2026-07-18 21:55 UTCVendor advisory
- 2026-07-18 18:01 UTCVendor advisory
- 2026-07-18 14:06 UTCVendor advisory
- 2026-07-18 10:11 UTCVendor advisory
- 2026-07-18 06:17 UTCVendor advisory
- 2026-07-18 02:23 UTCVendor advisory
- 2026-07-17 22:29 UTCVendor advisory
- 2026-07-17 18:35 UTCVendor advisory
- 2026-07-17 14:42 UTCVendor advisory
- 2026-07-17 10:48 UTCVendor advisory
- 2026-07-17 06:52 UTCVendor advisory
- 2026-07-17 02:58 UTCVendor advisory
- 2026-07-16 23:03 UTCVendor advisory
- 2026-07-16 19:09 UTCVendor advisory
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 15:14 UTCVendor advisory
- 2026-07-16 11:19 UTCVendor advisory
- 2026-07-16 07:25 UTCVendor advisory
- 2026-07-16 03:31 UTCVendor advisory
- 2026-07-15 23:37 UTCVendor advisory
- 2026-07-15 19:43 UTCVendor advisory
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 15:49 UTCVendor advisory
- 2026-07-15 15:04 UTCCISA KEV update
- 2026-07-15 11:55 UTCVendor advisory
- 2026-07-15 08:01 UTCVendor advisory
- 2026-07-15 04:07 UTCVendor advisory
- 2026-07-15 00:11 UTCVendor advisory
- 2026-07-14 20:17 UTCVendor advisory
- 2026-07-14 18:05 UTCCISA KEV update
- 2026-07-14 16:23 UTCVendor advisory
- 2026-07-14 12:29 UTCVendor advisory
- 2026-07-14 08:36 UTCVendor advisory
- 2026-07-14 04:40 UTCVendor advisory
- 2026-07-14 00:46 UTCVendor advisory
- 2026-07-13 20:52 UTCVendor advisory
- 2026-07-13 17:07 UTCCISA KEV update
- 2026-07-13 16:58 UTCVendor advisory
- 2026-07-13 13:04 UTCVendor advisory
- 2026-07-13 09:10 UTCVendor advisory
- 2026-07-13 05:17 UTCVendor advisory
- 2026-07-13 01:23 UTCVendor advisory
- 2026-07-12 21:29 UTCVendor advisory
- 2026-07-12 17:35 UTCVendor advisory
- 2026-07-12 13:40 UTCVendor advisory
- 2026-07-12 09:46 UTCVendor advisory
- 2026-07-12 05:51 UTCVendor advisory
- 2026-07-12 01:57 UTCVendor advisory
- 2026-07-11 22:03 UTCVendor advisory
- 2026-07-11 18:09 UTCVendor advisory
- 2026-07-11 14:15 UTCVendor advisory
- 2026-07-11 10:20 UTCVendor advisory
- 2026-07-11 06:26 UTCVendor advisory
- 2026-07-11 02:32 UTCVendor advisory
- 2026-07-10 22:38 UTCVendor advisory
- 2026-07-10 18:44 UTCVendor advisory
- 2026-07-10 17:52 UTCCISA KEV update
- 2026-07-10 14:50 UTCVendor advisory
- 2026-07-10 10:57 UTCVendor advisory
- 2026-07-10 07:00 UTCVendor advisory
- 2026-07-10 03:06 UTCVendor advisory
- 2026-07-09 23:13 UTCVendor advisory
- 2026-07-09 19:17 UTCVendor advisory
- 2026-07-09 19:06 UTCEPSS rescore
- 2026-07-09 15:24 UTCVendor advisory
- 2026-07-09 11:29 UTCVendor advisory
Publicly available exploits
(10 references)Working exploit code is in the public domain (8 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoClizhianyuguangming/TomcatScanProFirst seen Aug 29, 2024
tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含
Open source ↗ - GitHub PoCxiaokp7/Tomcat_PUT_GUI_EXPFirst seen Mar 10, 2023
Tomcat PUT方法任意文件写入(CVE-2017-12615)exp
Open source ↗ - GitHub PoCtpt11fb/AttackTomcatFirst seen Nov 13, 2022
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
Open source ↗ - GitHub PoC1337g/CVE-2017-12615First seen Dec 26, 2017
CVE-2017-12615 Tomcat RCE (TESTED)
Open source ↗ - GitHub PoCwsg00d/cve-2017-12615First seen Nov 1, 2017
tomcat-put-cve-2017-12615
Open source ↗ - GitHub PoCzi0Black/POC-CVE-2017-12615-or-CVE-2017-12717First seen Oct 6, 2017
CVE-2017-12617 and CVE-2017-12615 for tomcat server
Open source ↗ - GitHub PoCmefulton/cve-2017-12615First seen Sep 25, 2017
just a python script for cve-2017-12615
Open source ↗ - GitHub PoCbreaktoprotect/CVE-2017-12615First seen Sep 23, 2017
POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability.
Open source ↗ - Exploit-DBEDB-42953First seen Sep 20, 2017
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)
Open source ↗ - Nucleihttp/cves/2017/CVE-2017-12615.yamlFirst seen Jan 1, 2017
Apache Tomcat Servers - Remote Code Execution
Open source ↗
Related CVEs(same vendor)
Frequently asked(6)
What is CVE-2017-12615?
When was CVE-2017-12615 disclosed?
Is CVE-2017-12615 actively exploited?
What is the CVSS score of CVE-2017-12615?
Which products are affected by CVE-2017-12615?
How do I remediate CVE-2017-12615?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2017-12615
Is Your Infrastructure Affected by CVE-2017-12615?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.