Skip to content

CVE-2013-4444

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0949 (9.5%)
Percentile: 92.9%
EPSS: 2026-05-06

Affects

apache:tomcat

Technical description

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.

Published: 9/12/2014, 1:55:06 AM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam