CVE-2017-12615: Apache Tomcat Servers - Remote Code Execution

HoneyLabs honeypots recorded 4 probes matching CVE-2017-12615 from 1 distinct source IP addresses in the last 7 days. Severity is rated high.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /poc.jsp?cmd=cat+%2Fetc%2Fpasswd

Addresses probing it

Source IPProbesNetworkCountry
109.224.17.2134Hulum Almustakbal Company for Communication Engineering and Services LtdIraq

Networks it comes from

ASNOrganisationProbesSource IPs
AS203214Hulum Almustakbal Company for Communication Engineering and Services Ltd41

Captured requests

  • /poc.jsp?cmd=cat+%2Fetc%2Fpasswd

HTTP client fingerprints (JA4H)

  • ge11nn05en_813e32c09d15

CVE report

CVE report

Open a specific CVE from the CVE tracker.