Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2013-4444 from the MITRE CVE dictionary dictionary and NIST NVD.
Not Vulnerable. This issue did not affect the versions of Tomcat and JBoss Web as shipped with any Red Hat product, as this flaw was handled by Red Hat as CVE-2013-2185. This flaw is to be considered a duplicate of CVE-2013-4444.
NOTE: The following CVSS v2 metrics and score provided are preliminary and subject to review.
Base Score | 7.5 |
---|---|
Base Metrics | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Access Vector | Network |
Access Complexity | Low |
Authentication | None |
Confidentiality Impact | Partial |
Integrity Impact | Partial |
Availability Impact | Partial |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Package | State |
---|---|---|
Red Hat JBoss Portal Platform 6 | jbossweb | Not affected |
Red Hat JBoss Operations Network 3 | jbossweb | Not affected |
Red Hat JBoss Fuse Service Works 6 | jbossweb | Not affected |
Red Hat JBoss Enterprise SOA Platform 5 | jbossweb | Not affected |
Red Hat JBoss Enterprise SOA Platform 4 | jbossweb | Not affected |
Red Hat JBoss EWS 2 | tomcat7 | Not affected |
Red Hat JBoss EWS 2 | tomcat6 | Not affected |
Red Hat JBoss EWS 1 | tomcat6 | Not affected |
Red Hat JBoss EWS 1 | tomcat5 | Not affected |
Red Hat JBoss EAP 6 | jbossweb | Not affected |
Red Hat JBoss EAP 5 | jbossweb | Not affected |
Red Hat JBoss EAP 4 | jbossweb | Not affected |
Red Hat JBoss Data Virtualization 6 | jbossweb | Not affected |
Red Hat JBoss Data Grid 6 | jbossweb | Not affected |
Red Hat Enterprise Linux 7 | tomcat | Not affected |
Red Hat Enterprise Linux 6 | tomcat6 | Not affected |