---
id: CVE-2013-4444
title: >-
  Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in
  certain situations involving outdated java.io.File code and a custom JMX
  configuration, allows remote attackers to execute arbitrary code by uploading
  and acce…
summary: >-
  Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in
  certain situations involving outdated java.io.File code and a custom JMX
  configuration, allows remote attackers to execute arbitrary code by uploading
  and acce…
severity: medium
cvss: 6.8
cvssVector: 'AV:N/AC:M/Au:N/C:P/I:P/A:P'
cwe:
  - CWE-94
vendor: apache
product: tomcat
affected:
  - tomcat <= 7.0.39
  - tomcat = 7.0.0
  - tomcat = 7.0.1
  - tomcat = 7.0.2
  - tomcat = 7.0.3
  - tomcat = 7.0.4
  - tomcat = 7.0.10
  - tomcat = 7.0.11
  - tomcat = 7.0.12
  - tomcat = 7.0.13
  - tomcat = 7.0.14
  - tomcat = 7.0.15
  - tomcat = 7.0.16
  - tomcat = 7.0.17
  - tomcat = 7.0.18
  - tomcat = 7.0.19
  - tomcat = 7.0.20
  - tomcat = 7.0.21
  - tomcat = 7.0.22
  - tomcat = 7.0.23
  - tomcat = 7.0.24
  - tomcat = 7.0.25
  - tomcat = 7.0.26
  - tomcat = 7.0.27
  - tomcat = 7.0.28
  - tomcat = 7.0.29
  - tomcat = 7.0.30
  - tomcat = 7.0.31
  - tomcat = 7.0.32
  - tomcat = 7.0.33
  - tomcat = 7.0.34
  - tomcat = 7.0.35
  - tomcat = 7.0.36
  - tomcat = 7.0.37
  - tomcat = 7.0.38
published: '2014-09-12'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T20:17:08.040'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2013-4444'
references:
  - url: 'http://archives.neohapsis.com/archives/bugtraq/2014-09/0075.html'
    label: secalert@redhat.com
  - url: 'http://marc.info/?l=bugtraq&m=144498216801440&w=2'
    label: secalert@redhat.com
  - url: 'http://openwall.com/lists/oss-security/2014/10/24/12'
    label: secalert@redhat.com
  - url: 'http://seclists.org/fulldisclosure/2021/Jan/23'
    label: secalert@redhat.com
  - url: 'http://tomcat.apache.org/security-7.html'
    label: secalert@redhat.com
  - url: 'http://www.debian.org/security/2016/dsa-3447'
    label: secalert@redhat.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
    label: secalert@redhat.com
  - url: 'http://www.securityfocus.com/bid/69728'
    label: secalert@redhat.com
  - url: 'http://www.securitytracker.com/id/1030834'
    label: secalert@redhat.com
  - url: >-
      https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04851013
    label: secalert@redhat.com
  - url: 'http://archives.neohapsis.com/archives/bugtraq/2014-09/0075.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://marc.info/?l=bugtraq&m=144498216801440&w=2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://openwall.com/lists/oss-security/2014/10/24/12'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2021/Jan/23'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-7.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.debian.org/security/2016/dsa-3447'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/69728'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1030834'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04851013
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.1399
epssPercentile: 0.9647
ingestedAt: '2026-10-09T21:12:42.314Z'
---

## Overview

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.

## Affected

- `tomcat <= 7.0.39`
- `tomcat = 7.0.0`
- `tomcat = 7.0.1`
- `tomcat = 7.0.2`
- `tomcat = 7.0.3`
- `tomcat = 7.0.4`
- `tomcat = 7.0.10`
- `tomcat = 7.0.11`
- `tomcat = 7.0.12`
- `tomcat = 7.0.13`
- `tomcat = 7.0.14`
- `tomcat = 7.0.15`
- `tomcat = 7.0.16`
- `tomcat = 7.0.17`
- `tomcat = 7.0.18`
- `tomcat = 7.0.19`
- `tomcat = 7.0.20`
- `tomcat = 7.0.21`
- `tomcat = 7.0.22`
- `tomcat = 7.0.23`
- `tomcat = 7.0.24`
- `tomcat = 7.0.25`
- `tomcat = 7.0.26`
- `tomcat = 7.0.27`
- `tomcat = 7.0.28`
- `tomcat = 7.0.29`
- `tomcat = 7.0.30`
- `tomcat = 7.0.31`
- `tomcat = 7.0.32`
- `tomcat = 7.0.33`
- `tomcat = 7.0.34`
- `tomcat = 7.0.35`
- `tomcat = 7.0.36`
- `tomcat = 7.0.37`
- `tomcat = 7.0.38`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
