CVE-2022-45935
published 2023-01-06CVE-2022-45935: Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.36%
28.1th percentile
Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit.
Vulnerable components includes the SMTP stack and IMAP APPEND command.
This issue affects Apache James server version 3.7.2 and prior versions.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | james | <= 3.7.2 | — |
| apache_software_foundation | apache_james_server | <= 3.7.2 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache James server allows an attacker with local access to access private user data in transit
osv·2023-01-06
CVE-2022-45935 [MEDIUM] Apache James server allows an attacker with local access to access private user data in transit
Apache James server allows an attacker with local access to access private user data in transit
Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit. Vulnerable components includes the SMTP stack and IMAP APPEND command. This issue affects Apache James server version 3.7.2 and prior versions.
GHSA
Apache James server allows an attacker with local access to access private user data in transit
ghsa·2023-01-06
CVE-2022-45935 [MEDIUM] CWE-200 Apache James server allows an attacker with local access to access private user data in transit
Apache James server allows an attacker with local access to access private user data in transit
Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit. Vulnerable components includes the SMTP stack and IMAP APPEND command. This issue affects Apache James server version 3.7.2 and prior versions.
Red Hat
apache-james: Temporary File Information Disclosure
vendor_redhat·2023-01-06·CVSS 5.5
CVE-2022-45935 [MEDIUM] CWE-200 apache-james: Temporary File Information Disclosure
apache-james: Temporary File Information Disclosure
Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit.
Vulnerable components includes the SMTP stack and IMAP APPEND command.
This issue affects Apache James server version 3.7.2 and prior versions.
Package: apache-james (Red Hat build of Apache Camel for Spring Boot 3) - Not affected
Package: apache-james (Red Hat build of Apicurio Registry 2) - Not affected
Package: apache-james (Red Hat Data Grid 8) - Not affected
Package: apache-james (Red Hat Decision Manager 7) - Not affected
Package: apache-james (Red Hat Fuse 7) - Not affected
Package: apache-james (Red Hat Integration Camel K 1) - Not affected
Package: apache-james (Red Hat
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-06
Published