Path traversal in Apache James - CVE-2015-7611

 

Path traversal in Apache James - CVE-2015-7611

Published: February 25, 2020


Vulnerability identifier: #VU25576
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-7611
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote authenticated user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences within username when creating new user account in Apache James Remote Administration Tool. A remote authenticated user can send a specially crafted POP3 request to create a user with malicious username and then execute the code, stored in the username by sending an email to this particular recipient.


Affected software

Apache James

How to mitigate CVE-2015-7611

Install update from vendor's website.

Apache James - update to 2.3.2.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins