CVE-2013-4444EPSS p96.5%
CVE-2013-4444CVE-2013-4444
apache / tomcat
Description
Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.
Scoring
| CVSS | 6.8 () |
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 13.99% probability of exploitation · percentile 96.5% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-09 |