Severity
5.5MEDIUM
EPSS
0.1%
top 68.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 6

Description

Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit. Vulnerable components includes the SMTP stack and IMAP APPEND command. This issue affects Apache James server version 3.7.2 and prior versions.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

3
CVEList
Apache James server: Temporary File Information Disclosure2023-01-06
OSV
Apache James server allows an attacker with local access to access private user data in transit2023-01-06
GHSA
Apache James server allows an attacker with local access to access private user data in transit2023-01-06

📋Vendor Advisories

1
Red Hat
apache-james: Temporary File Information Disclosure2023-01-06
CVE-2022-45935 (MEDIUM CVSS 5.5) | Usage of temporary files with insec | cvebase.io