Apache Tomcat on Windows Remote Code Execution Vulnerability
Apache · Tomcat
Date added (CISA)
2022-03-25
Remediation due
2022-04-15
Known ransomware use
Yes
Remediation priority
P1 — known ransomware use · past CISA due date
Description
When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.