CVE-2013-4444 describes an unrestricted file upload vulnerability in Apache Tomcat 7.x before version 7.0.40. This flaw, under specific conditions involving outdated Java I/O code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and then accessing a malicious JSP file. With a CVSS score of 6.8 (Medium), it carries a moderate risk due to network-based attacks with medium complexity, potentially leading to partial confidentiality, integrity, and availability impacts. While the FAUCET Risk Score is high at 85/100, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.0.39CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
7.0.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:* | ||
7.0.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:* | ||
7.0.1CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:* | ||
7.0.2CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:7.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.