Apache Tomcat Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2013-4444
Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40 in certain situations involving outdated java.io.File code and a custom JMX configuration allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.