CVE-2025-49656
published 2025-07-21CVE-2025-49656: Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.40%
69.4th percentile
Users with administrator access can create databases files outside the files area of the Fuseki server.
This issue affects Apache Jena version up to 5.4.0.
Users are recommended to upgrade to version 5.5.0, which fixes the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | jena | < 5.5.0 | 5.5.0 |
| apache_software_foundation | apache_jena | <= 5.4.0 | — |
| debian | apache-jena | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.apache.jena/jena-arq: Apache Jena path traversal
vendor_redhat·2025-07-21·CVSS 7.5
CVE-2025-49656 [HIGH] CWE-22 org.apache.jena/jena-arq: Apache Jena path traversal
org.apache.jena/jena-arq: Apache Jena path traversal
Users with administrator access can create databases files outside the files area of the Fuseki server.
This issue affects Apache Jena version up to 5.4.0.
Users are recommended to upgrade to version 5.5.0, which fixes the issue.
A path traversal flaw has been discovered in Apache Jena. This flaw allows an attacker to create files outside of the designated file area.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: jena-arq (Red Hat AMQ Clients) - Fix deferred
Package: jena-arq (Red Hat Data Grid 8) - Fix deferred
Package: jena-a
Debian
CVE-2025-49656: apache-jena - Users with administrator access can create databases files outside the files are...
vendor_debian·2025·CVSS 7.5
CVE-2025-49656 [HIGH] CVE-2025-49656: apache-jena - Users with administrator access can create databases files outside the files are...
Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue.
Scope: local
bookworm: open
forky: open
sid: open
trixie: open
GHSA
Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki server
ghsa·2025-07-21
CVE-2025-49656 [MEDIUM] CWE-22 Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki server
Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki server
Users with administrator access can create databases files outside the files area of the Fuseki server.
This issue affects Apache Jena version up to 5.4.0.
Users are recommended to upgrade to version 5.5.0, which fixes the issue.
OSV
CVE-2025-49656: Users with administrator access can create databases files outside the files area of the Fuseki server
osv·2025-07-21·CVSS 7.5
CVE-2025-49656 [HIGH] CVE-2025-49656: Users with administrator access can create databases files outside the files area of the Fuseki server
Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue.
OSV
Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki server
osv·2025-07-21
CVE-2025-49656 [MEDIUM] Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki server
Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki server
Users with administrator access can create databases files outside the files area of the Fuseki server.
This issue affects Apache Jena version up to 5.4.0.
Users are recommended to upgrade to version 5.5.0, which fixes the issue.
No detection rules found.
No public exploits indexed.
2025-07-21
Published