Allaire Security Bulletin (ASB00- 29) : JRun 2.3.3: Patch Available for JSP Execution of Arbitrary File Security Issue
Under certain circumstances, it is possible to insert executable code in the form of JSP tags and cause the code to be compiled and executed using JRun's handlers. Here's a link to the patch:
Allaire Security Bulletin (ASB00-29) (Allaire Security Bulletin)