CVE-2017-12628
The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.76%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only on local-host, this vulnerability can only be used for privilege escalation. Release 3.0.1 upgrades the incriminated library.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.76% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- apache/james server
- Source
- security@apache.org
References
- http://www.securityfocus.com/bid/101532Third Party Advisory, VDB Entry
- https://www.mail-archive.com/server-user%40james.apache.org/msg15633.html
- http://www.securityfocus.com/bid/101532Third Party Advisory, VDB Entry
- https://www.mail-archive.com/server-user%40james.apache.org/msg15633.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.