CVE Database
/

CVE-2023-26269

Back to search

CVE-2023-26269

Published: Apr 3, 2023

Modified: Feb 13, 2025

PUBLISHED

Description

Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user. Administrators are advised to disable JMX, or set up a JMX password. Note that version 3.7.4 onward will set up a JMX password automatically for Guice users.

VendorProductVersions

Apache Software Foundation

Apache James server

affected
0 - <= 3.7.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now