Direct HTTP Parameters to Command Execution
Java applications pass HTTP request parameters (from ServletRequest.getParameter(), @RequestParam, etc.) directly to ProcessBuilder or Runtime.exec() without validation. User-controlled input becomes part of executed system commands, allowing attackers to inject malicious command sequences.