Apache James CVE-2017-12628 Arbitrary Command Execution Vulnerability
BID:101532
Info
Apache James CVE-2017-12628 Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 101532 |
| Class: | Design Error |
| CVE: |
CVE-2017-12628 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2017 12:00AM |
| Updated: | Oct 20 2017 12:00AM |
| Credit: | Benoit Tellier. |
| Vulnerable: |
Apache James 3.0 Apache James 2.2 Apache James 1.8.2 Apache James 1.8.1 |
| Not Vulnerable: |
Apache James 3.0.1 |
Discussion
Apache James CVE-2017-12628 Arbitrary Command Execution Vulnerability
Apache James is prone to an arbitrary command-execution vulnerability.
An attacker can exploit this issue to execute arbitrary command on the affected system. This may aid in further attacks.
Apache James versions prior to 3.0.1 are affected.
Apache James is prone to an arbitrary command-execution vulnerability.
An attacker can exploit this issue to execute arbitrary command on the affected system. This may aid in further attacks.
Apache James versions prior to 3.0.1 are affected.
Exploit / POC
Apache James CVE-2017-12628 Arbitrary Command Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache James CVE-2017-12628 Arbitrary Command Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache James CVE-2017-12628 Arbitrary Command Execution Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)
- Announce: Apache James 3.0.1 security release (Mail)
- Apache James 3.0.1 security release (Seclists.org)