When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Original announcement is here: http://mail-archives.apache.org/mod_mbox/www-announce/201709.mbox/%3Cde541c4a-55b1-a4d3-4fbe-f8e3800b920f@apache.org%3E
RedShield customers are protected as the HTTP PUTS verb is blocked by default. Any customers running Apache Tomcat on Windows please contact RedShield support.
Comments