""ET WEB_SPECIFIC_APPS Apache Tomcat Possible CVE-2017-12617 JSP Upload Bypass Attempt""

SID: 2024811

Revision: 3

Class Type: web-application-attack

Metadata: affected_product Apache_Tomcat, attack_target Web_Server, created_at 2017_10_05, cve CVE_2017_12617, deployment Datacenter, signature_severity Major, updated_at 2017_11_30

Reference:

  • cve

  • 2017-12615

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: $HTTP_SERVERS

Destination Port: $HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "DELETE"

  • Value: ".jsp/"

Within:

PCRE: "/.jsp\/[^\x2f]*$/Ui"

Special Options:

  • http_method

  • http_uri

  • nocase

source