← All CVEs

CVE-2013-4444

medium · 6.8

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.

6.8
CVSS
14.0%
EPSS (exploit prob.)
96th
EPSS percentile
2014-09-12
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
apachetomcat<= 7.0.39
apachetomcat7.0.0
apachetomcat7.0.0
apachetomcat7.0.1
apachetomcat7.0.2
apachetomcat7.0.2
apachetomcat7.0.3
apachetomcat7.0.4
apachetomcat7.0.4
apachetomcat7.0.10
apachetomcat7.0.11
apachetomcat7.0.12
apachetomcat7.0.13
apachetomcat7.0.14
apachetomcat7.0.15
apachetomcat7.0.16
apachetomcat7.0.17
apachetomcat7.0.18
apachetomcat7.0.19
apachetomcat7.0.20
apachetomcat7.0.21
apachetomcat7.0.22
apachetomcat7.0.23
apachetomcat7.0.24
apachetomcat7.0.25
apachetomcat7.0.26
apachetomcat7.0.27
apachetomcat7.0.28
apachetomcat7.0.29
apachetomcat7.0.30
apachetomcat7.0.31
apachetomcat7.0.32
apachetomcat7.0.33
apachetomcat7.0.34
apachetomcat7.0.35
apachetomcat7.0.36
apachetomcat7.0.37
apachetomcat7.0.38

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-4444