CVE-2017-12617 is an unrestricted JSP upload vulnerability in Apache Tomcat and a remote-code-execution bypass for CVE-2017-12615. On affected Windows Tomcat deployments, a specially crafted HTTP PUT request can upload a JSP file when HTTP PUT is enabled and the Default servlet or relevant servlet context is writable because its readonly initialization parameter is set to false. Requesting the uploaded JSP causes Tomcat to execute the code it contains. Affected upstream versions are Tomcat 9.0.0.M1 through 9.0.0, 8.5.0 through 8.5.22, 8.0.0.RC1 through 8.0.46, and 7.0.0 through 7.0.81.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module: 'tomcat_jsp_upload_bypass.rb', which exploits CVE-2017-12617 in Apache Tomcat. The exploit leverages a misconfiguration that allows attackers to upload a JSP file via an HTTP PUT request and then execute it, resulting in remote code execution. The module is weaponized, supporting customizable payloads (such as reverse shells) via Metasploit's payload system. The exploit targets both Linux and Windows platforms where Tomcat is running. The main attack vector is network-based, requiring access to the Tomcat HTTP service (default port 8080). The module defines endpoints for uploading and executing the payload, and includes a check method to verify vulnerability. The repository is structured as a typical Metasploit exploit module, written in Ruby, and is ready for operational use within the Metasploit framework.
This repository contains a Python exploit script (tomcat-cve-2017-12617.py) targeting CVE-2017-12617, a remote code execution vulnerability in Apache Tomcat (versions before 9.0.1, 8.5.23, 8.0.47, and 7.0.82) when HTTP PUT is enabled and the 'readonly' parameter is set to false. The script provides three main functionalities: (1) checking if a single target is vulnerable by uploading a test JSP file and verifying its execution, (2) uploading a JSP webshell to a vulnerable server and providing an interactive shell for command execution, and (3) scanning a list of hosts for vulnerability. The exploit works by sending HTTP PUT requests to upload JSP files to the server, then accessing them via HTTP GET to trigger code execution. The payload is a JSP webshell that executes arbitrary system commands via the 'cmd' parameter. The repository is structured with a single main exploit script, a README with usage instructions, and standard project files. No hardcoded IPs or domains are present; the target is specified by the user at runtime.
This repository contains a Python exploit script (CVE-2017-12617.py) targeting Apache Tomcat servers vulnerable to CVE-2017-12617. The exploit works by uploading a malicious JSP file (reverse shell) to the server using an HTTP PUT request, exploiting a misconfiguration that allows arbitrary file uploads. The payload, a JSP reverse shell, is dynamically generated to connect back to an attacker-specified host and port. The script is structured as a class with methods for configuring the payload, detecting the vulnerability, and performing the exploit. The main entry point is the CVE-2017-12617.py file. The README is minimal and does not provide usage instructions. No hardcoded network endpoints are present, but the payload file path '/YKSBjswJKSWInkjw.jsp' is used for the upload. The exploit is operational and provides a working reverse shell if the target is vulnerable.
This repository contains a Python 3 exploit script (CVE-2017-12617.py) targeting Apache Tomcat servers vulnerable to CVE-2017-12617. The exploit abuses the HTTP PUT method (if enabled) to upload a malicious JSP file (webshell) to the server. Once uploaded, the script triggers the webshell, which initiates a reverse shell connection back to the attacker's machine using the provided IP and port. The exploit is operational and provides a working reverse shell if the target is vulnerable. The repository also includes a README with usage instructions and a LICENSE file. The main exploit logic is contained in a single Python file, which generates and uploads the JSP payload, then listens for the reverse shell connection using netcat. No detection or scanning functionality is present; the script is designed for exploitation only.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown
An Apache Tomcat remote-code-execution bypass for CVE-2017-12615.
A Tomcat remote code execution flaw, described as a bypass for CVE-2017-12615, that allows JSP upload and code execution when a servlet context permits writes and HTTP PUT requests.
A remote code-execution vulnerability in Tomcat: an attacker can upload a JSP file and execute code when a servlet context permits writes (readonly=false) and HTTP PUT requests.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.