cbcvebase.
CVE-2022-45935
published 2023-01-06

CVE-2022-45935: Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit…

PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.36%
28.1th percentile
Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit. Vulnerable components includes the SMTP stack and IMAP APPEND command. This issue affects Apache James server version 3.7.2 and prior versions.

Affected

2 ranges
VendorProductVersion rangeFixed in
apachejames<= 3.7.2
apache_software_foundationapache_james_server<= 3.7.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.