Vulnerable components includes the SMTP stack and IMAP APPEND command.
This issue affects Apache James server version 3.7.2 and prior versions.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0555 | Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit. Vulnerable components includes the SMTP stack and IMAP APPEND command. This issue affects Apache James server version 3.7.2 and prior versions. |
Github GHSA |
GHSA-v6vp-62vc-84qw | Apache James server allows an attacker with local access to access private user data in transit |
Thu, 10 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-04-10T13:35:31.647Z
Reserved: 2022-11-27T08:53:19.892Z
Link: CVE-2022-45935
Updated: 2024-08-03T14:24:03.215Z
Status : Modified
Published: 2023-01-06T10:15:10.447
Modified: 2025-04-10T14:15:24.033
Link: CVE-2022-45935
OpenCVE Enrichment
No data.
EUVD
Github GHSA