S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2017-12615 Scanner

CVE-2017-12615 scanner - Remote Code Execution (RCE) vulnerability in Apache Tomcat

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2017-12615
8.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache Tomcatby Apache Software Foundation
7.0.0 to 7.0.79
Updated Aug 22, 2026View on NVD →
Detail

Apache Tomcat (sometimes referred to simply as Tomcat) is a popular Java-based web server and servlet container that is used for serving dynamic webpages and web applications. It is a free and open-source software, providing a flexible and scalable environment for deploying Java web applications. Apache Tomcat provides various features like authentication, access control, virtual hosting, and many more, making it a popular choice among web developers and businesses.

One critical vulnerability that was detected in Apache Tomcat is the CVE-2017-12615 vulnerability. This vulnerability arises when a specially crafted HTTP PUT request is sent to the server with readonly initialization parameters of the default set to false. This can allow an attacker to upload a JSP file to the server that, when executed, can run malicious code on the server.

If exploited, this vulnerability can lead to significant security implications, including data theft, server takeover, and unauthorized access to sensitive information. Additionally, in some cases, the vulnerability could lead to a complete server compromise, leading to a significant impact on business productivity and financial loss.

At s4e.io, we offer a comprehensive platform that allows users to scan their digital assets for vulnerabilities like CVE-2017-12615 quickly and easily. Our pro features provide advanced security testing capabilities and detailed reports to help businesses stay safe and secure. Don't risk your digital assets to vulnerabilities - sign up for s4e.io today.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Upgrade to the latest version of Apache Tomcat
  • Set the readonly initialization parameter of the default to true
  • Disable HTTP PUTs entirely unless explicitly required
  • Monitor and review network traffic for potential malicious activity
  • Configure access controls and user permissions to limit unauthorized access to sensitive files.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-12615 scanner - Remote Code Execution (RCE) vulnerability in Apache Tomcat | S4E