Apache james
This hub aggregates every CVE we track for Apache james, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.
7
CVEs tracked
1
Critical
3
High
0
In CISA KEV
Severity distribution
HIGH3MEDIUM3CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 7 most recently published vulnerabilities affecting Apache james.
- CVE-2022-28220STARTTLS command injection in Apache JAMES7.5
- CVE-2022-22931Path traversal in Apache James 3.6.14.3
- CVE-2021-40525Sieve file storage vulnerable to path traversal attacks9.1
- CVE-2021-40111Apache James IMAP parsing Denial Of Service6.5
- CVE-2021-40110Apache James IMAP vulnerable to a ReDoS7.5
- CVE-2021-38542Apache James vulnerable to STARTTLS command injection (IMAP and POP3)5.9
- CVE-2017-12628The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX s...7.8
Product normalization is registry-driven with AI assist and human review. How it works