Known vulnerabilities in Apache James 3.0-beta3
Vendor:
Apache Foundation
Software:
Apache James
Version:
3.0-beta3
Software CPE:
cpe:2.3:a:apache_foundation:james:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
7
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Vulnerabilities by Severity
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU74278 - Missing Authorization CVE-2023-26269 |
CWE-862 | Low | 3.7.4 | 03.04.2023 |
SB2023040307 |
||
| #VU67496 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2022-28220 |
CWE-300 | Medium | 3.7.1 | 20.09.2022 |
SB2022092027 |
||
| #VU59162 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2021-40111 |
CWE-835 | Medium | 3.6.1 | 04.01.2022 |
SB2022010404 |
||
| #VU59161 - Command injection CVE-2021-38542 |
CWE-77 | Medium | 3.6.1 | 04.01.2022 |
SB2022010404 |
||
| #VU59160 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2021-40525 |
CWE-22 | Medium | 3.6.1 | 04.01.2022 |
SB2022010404 |
||
| #VU59154 - Incorrect Regular Expression CVE-2021-40110 |
CWE-185 | Low | 3.6.1 | 04.01.2022 |
SB2022010404 |
||
| #VU25579 - Deserialization of Untrusted Data CVE-2017-12628 |
CWE-502 | Low | 3.0.1 | 25.02.2020 |
SB2017102014 |