Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-26269
HistoryApr 03, 2023 - 8:15 a.m.

Authentication flaw

2023-04-0308:15:00
PRIOn knowledge base
www.prio-n.com
5
apache james
server
authentication
flaw
privilege escalation
jmx
management
service
disable
password
guice
nvd

8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a
malicious local user.

Administrators are advised to disable JMX, or set up a JMX password.

Note that version 3.7.4 onward will set up a JMX password automatically for Guice users.

CPENameOperatorVersion
jameslt3.7.4

8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for PRION:CVE-2023-26269