cbcvebase.

Apache Software Foundation Apache James Server vulnerabilities

5 known vulnerabilities affecting apache_software_foundation/apache_james_server.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2023-51518P2CRITICALCVSS 9.8≤ 3.7.4≥ 3.8, ≤ 3.8.02024-02-27
CVE-2023-51518 [CRITICAL] CWE-502 CVE-2023-51518: Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-aut Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Given a deserialisation gadjet, this could be leveraged as part of an exploit chain that could result in privilege escalation. Note that by default JMX endpoint is only bound locally. We recommend user
nvd
CVE-2023-51747P3HIGHCVSS 7.1≤ 3.7.4≥ 3.8, ≤ 3.8.02024-02-27
CVE-2023-51747 [HIGH] CWE-20 CVE-2023-51747: Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop, allowing for instance to bypass SPF checks. The patch implies enforcement of CRLF
nvd
CVE-2024-45626P3HIGHCVSS 7.5≥ 3.8.0, ≤ 3.8.1≤ 3.7.52025-02-06
CVE-2024-45626 [HIGH] CWE-400 CVE-2024-45626: Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subj Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service. Users are recommended to upgrade to version 3.7.6 and 3.8.2, which fix this issue.
nvd
CVE-2024-34055P4MEDIUMCVSS 6.5≤ 3.7.5≥ 3.8.0, ≤ 3.8.12024-06-05
CVE-2024-34055 [MEDIUM] CWE-770 CVE-2024-34055: Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbound Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command.
nvd
CVE-2022-45935P4MEDIUMCVSS 5.5≤ 3.7.22023-01-06
CVE-2022-45935 [MEDIUM] CWE-668 CVE-2022-45935: Usage of temporary files with insecure permissions by the Apache James server allows an attacker wit Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit. Vulnerable components includes the SMTP stack and IMAP APPEND command. This issue affects Apache James server version 3.7.2 and prior versions.
nvd
Apache Software Foundation Apache James Server vulnerabilities | cvebase