CVE-2013-4444 REJECTED

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.

EPSS 20.29% · 95.5th percentile

Risk Scores

EPSS Score
20.29%
95.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTStomcat70, 7.0.42-1, 7.0.47-1

Timeline

References

Open in Interactive Console →