A remote code execution vulnerability has been reported in Apache Tomcat. The vulnerability is due to insufficient validation of PUT requests. A remote attacker can exploit this vulnerability by sending a specially crafted request containing a JSP page to the vulnerable server. This can result in remote code execution in the context of the affected service. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None