Command Injection in Jakarta Mail - CVE-2025-7962

 

Command Injection in Jakarta Mail - CVE-2025-7962

Published: August 21, 2025


Vulnerability identifier: #VU114346
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-7962
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SMTP commands on the system.

The vulnerability exists due to insufficient input validation when handling CR-LF characters in UTF-8 encoding. A remote attacker can pass specially crafted input to the application and execute arbitrary SMTP commands on the server.


Affected software

Jakarta Mail
IBM App Connect Enterprise
IBM CICS TX Advanced
IBM CICS TX Standard
WebSphere Service Registry and Repository
IBM Maximo Asset Management
Jazz for Service Management
IBM SPSS Analytic Server
IBM Security Guardium Key Lifecycle Manager (GKLM)
Jira Service Management Data Center
IBM Sterling Partner Engagement Manager
IBM Tivoli Monitoring
IBM Tivoli Netcool Impact
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM SPSS Collaboration and Deployment Services
WebSphere Remote Server
IBM Common Licensing
IBM Rational ClearCase
IBM Rational ClearQuest
Jira Software Data Center
IBM Security Verify Governance
IBM Business Automation Workflow
IBM Maximo Application Suite - Manage Component
Enterprise Application Service for Java
Operations Analytics - Log Analysis
PowerVM NovaLink
Tivoli Network Manager IP Edition
IBM Tivoli Netcool Configuration Manager
Engineering Test Management
Tivoli Composite Application Manager for Application Diagnostics
Maximo Application Suite - Predict Component
Maximo Application Suite - Monitor Component
IBM OpenPages with Watson
Rational Performance Tester
IBM Security Verify Directory
Integration Bus for z/OS
Verify Identity Access Digital Credentials
DevOps Test Performance
DevOps Code ClearCase
ApplinX
Oracle Retail Xstore Point of Service
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect for Space Management
Storage Protect for Virtual Environments: Data Protection for Hyper-V
IBM Copy Services Manager
Jakarta Mail API
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
Basesystem Module
openSUSE Leap
openEuler
Openmeetings
IBM WebSphere Application Server
IBM WebSphere Application Server Liberty
IBM Security Verify Access
IBM Cognos Command Center
Siebel CRM End User
Oracle Communications Cloud Native Core Console
Oracle Retail Xstore Office
javamail
javamail-javadoc
jakarta-mail
Operational Decision Manager

How to mitigate CVE-2025-7962

Install updates from vendor's website.

Jakarta Mail - addressed in versions 1.6.8, 2.0.2
Jakarta Mail API - update to 2.1.3-3
PowerVM NovaLink - addressed in versions 2.1.1-260119, 2.2.1.1-260119, 2.3.2-260116
Openmeetings - update to 8.1.0
Tivoli Network Manager IP Edition - update to 4.2.0.23
Jira Service Management Data Center - addressed in versions 5.12.27, 10.3.10, 11.0.0, 11.0.1
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.23
IBM Tivoli Netcool Impact - update to 7.1.0.38
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
IBM WebSphere Application Server - addressed in versions 8.5.5.29, 9.0.5.27
Maximo Application Suite - Predict Component - addressed in versions 8.8.13, 8.9.15, 9.0.12, 9.1.5
Maximo Application Suite - Monitor Component - addressed in versions 8.10.27, 8.11.25, 9.0.17, 9.1.7
Jira Software Data Center - addressed in versions 9.12.27, 10.3.10, 11.0.1
IBM Security Verify Directory - update to 10.0.4.3
IBM Security Verify Governance - update to 10.0.2.0.7
IBM Cognos Command Center - update to 10.2.5 FP1 IF2
DevOps Test Performance - update to 11.0.8
IBM App Connect Enterprise - addressed in versions 12.0.12.21, 13.0.6.0
IBM WebSphere Application Server Liberty - update to 25.0.0.12
javamail - update to 1.6.2-150200.3.7.1
javamail-javadoc - update to 1.6.2-150200.3.7.1
jakarta-mail - update to 1.6.7-4
Storage Protect Client - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.2.1
Storage Protect for Space Management - update to 8.2.1
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.2.1
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.34, 8.7.28, 9.0.21, 9.1.8
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 49, 8.11.1 Interim fix 47, 8.12.0.1 Interim fix 31, 9.0.0.1 Interim fix 15, 9.5.0.0 Interim fix 7
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix44, 11.1.0.0 ifix36
IBM CICS TX Standard - update to 11.1.0.0 ifix37

External References

Related Security Bulletins