CVE Database
/

CVE-2017-12628

Back to search

CVE-2017-12628

Published: Oct 20, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only on local-host, this vulnerability can only be used for privilege escalation. Release 3.0.1 upgrades the incriminated library.

VendorProductVersions

Apache Software Foundation

Apache James

affected
3.0.0

References

101532
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now