CVE-2017-12615General(apache / 7-mode_transition_tool)

LOWCVSS 8.1 · HIGHCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

1.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-04-15. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 7-mode_transition_tool
  • enterprise_linux_desktop
  • enterprise_linux_eus
  • enterprise_linux_eus_compute_node

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
7-mode_transition_toolenterprise_linux_desktopenterprise_linux_eusenterprise_linux_eus_compute_nodeenterprise_linux_for_ibm_z_systemsenterprise_linux_for_ibm_z_systems_eusenterprise_linux_for_power_big_endianenterprise_linux_for_power_big_endian_eusenterprise_linux_for_power_little_endianenterprise_linux_for_power_little_endian_eus

25 versions affected across 23 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Sam Maina 🦍@swmaina
    General

    @Mike_Kutola A system unmaintained for 5 years is most likely insecure. It usually means no security updates or bug patches for 5yrs, and there's a large window in which even legacy exploits can cause mayhem, e.g. RCE flaws such as CVE-2017-12615 and CVE-2019-0232 for Tomcat 7.

    Post summary

    The tweet notes that an unmaintained Tomcat 7 installation is vulnerable to RCE CVEs CVE-2017-12615 and CVE-2019-0232, highlighting the risk of legacy exploits.

    00020379
    2.5K followersView on X
CPE platform detail51 entries

51 of 51 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---
OSmicrosoftwindows---
Appnetapp7-mode_transition_tool---
Appnetapponcommand_balance---
Appnetapponcommand_shift---
OSredhatenterprise_linux_desktop6.0--
OSredhatenterprise_linux_desktop7.0--
OSredhatenterprise_linux_eus7.4--
OSredhatenterprise_linux_eus7.5--
OSredhatenterprise_linux_eus7.6--
OSredhatenterprise_linux_eus7.7--
OSredhatenterprise_linux_eus_compute_node7.4--
OSredhatenterprise_linux_eus_compute_node7.5--
OSredhatenterprise_linux_eus_compute_node7.6--
OSredhatenterprise_linux_eus_compute_node7.7--
OSredhatenterprise_linux_for_ibm_z_systems7.0_s390x--
OSredhatenterprise_linux_for_ibm_z_systems_eus7.4_s390x--
OSredhatenterprise_linux_for_ibm_z_systems_eus7.5_s390x--
OSredhatenterprise_linux_for_ibm_z_systems_eus7.6_s390x--
OSredhatenterprise_linux_for_ibm_z_systems_eus7.7_s390x--
OSredhatenterprise_linux_for_power_big_endian7.0_ppc64--
OSredhatenterprise_linux_for_power_big_endian_eus7.4_ppc64--
OSredhatenterprise_linux_for_power_big_endian_eus7.5_ppc64--
OSredhatenterprise_linux_for_power_big_endian_eus7.6_ppc64--
OSredhatenterprise_linux_for_power_big_endian_eus7.7_ppc64--
OSredhatenterprise_linux_for_power_little_endian7.0_ppc64le--
OSredhatenterprise_linux_for_power_little_endian_eus7.4_ppc64le--
OSredhatenterprise_linux_for_power_little_endian_eus7.5_ppc64le--
OSredhatenterprise_linux_for_power_little_endian_eus7.6_ppc64le--
OSredhatenterprise_linux_for_power_little_endian_eus7.7_ppc64le--
OSredhatenterprise_linux_for_scientific_computing7.0--
OSredhatenterprise_linux_server6.0--
OSredhatenterprise_linux_server7.0--
OSredhatenterprise_linux_server_aus7.4--
OSredhatenterprise_linux_server_aus7.6--
OSredhatenterprise_linux_server_aus7.7--
OSredhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions7.4_ppc64le--
OSredhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions7.6_ppc64le--
OSredhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions7.7_ppc64le--
OSredhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions9.2_ppc64le--
OSredhatenterprise_linux_server_tus7.4--
OSredhatenterprise_linux_server_tus7.6--
OSredhatenterprise_linux_server_tus7.7--
Appredhatenterprise_linux_server_update_services_for_sap_solutions7.4--
Appredhatenterprise_linux_server_update_services_for_sap_solutions7.6--
Appredhatenterprise_linux_server_update_services_for_sap_solutions7.7--
OSredhatenterprise_linux_workstation6.0--
OSredhatenterprise_linux_workstation7.0--
Appredhatjboss_enterprise_web_server2.0.0--
Appredhatjboss_enterprise_web_server3.0.0--
Appredhatjboss_enterprise_web_server_text-only_advisories---

Explore more