📦 James

by Apache

🔍 What is James?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-51518

CRITICAL CVSS 9.8 Feb 27, 2024

Apache James email servers prior to versions 3.7.5 and 3.8.0 have a pre-authentication deserialization vulnerability in their JMX endpoint. Attackers with local access can exploit this to execute arbi...

CVE-2021-40525

CRITICAL CVSS 9.1 Jan 4, 2022

CVE-2021-40525 is a path traversal vulnerability in Apache James ManagedSieve implementation that allows attackers to read and write arbitrary files on the server. This affects Apache James email serv...

CVE-2023-51747

HIGH CVSS 7.1 Feb 27, 2024

This SMTP smuggling vulnerability in Apache James allows attackers to manipulate email line delimiters to forge SMTP envelopes, potentially bypassing SPF authentication checks. It affects Apache James...