Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45700
HistoryFeb 29, 2024 - 8:00 a.m.

Deserialization Of Untrusted Data

2024-02-2908:00:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4
org.apache.james
deserialization
untrusted data
jmx endpoint
vulnerability
privilege escalation
remote code execution
software

7.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

org.apache.james: james-server is vulnerable to Deserialization Of Untrusted Data. The vulnerability is due to a JMX endpoint being exposed on localhost, allowing exploitation with a deserialization gadget, potentially resulting in privilege escalation or remote code execution.

7.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for VERACODE:45700