VDB

RHSA-2013:1194

RHSA-2013:1194 PUBLISHED CVSS 7.5 HIGH

It was possible for an attacker, using complex and limited conditions, to upload a malicious JSP to a Tomcat server and then trigger the execution of that JSP.

Risk Scores

CVSS 2.0
7.5

Affected Products

VendorProductVersions
Red HatRed Hat JBoss Enterprise Application Platform 6.1

Timeline

  • Sep 3, 2013 CVE Published
  • Jan 28, 2026 CVE Updated
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Security Advisory
  • Apr 29, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›