Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45677
HistoryFeb 28, 2024 - 12:16 p.m.

SMTP Smuggling

2024-02-2812:16:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
smtp
apache james
vulnerability
line delimiter
spf checks
exploit

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.5%

Apache James is vulnerable to SMTP Smuggling. The vulnerability is due to the lenient behavior in line delimiter handling which creates a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop, allowing for instance to bypass SPF checks.

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.5%