CVE-2021-40525
9.1
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. Distributed and Cassandra based products are also not impacted.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 3.71% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-01-04 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| apache | james |
References
- http://www.openwall.com/lists/oss-security/2022/01/04/4
- http://www.openwall.com/lists/oss-security/2022/02/07/1
- https://www.openwall.com/lists/oss-security/2022/01/04/4
- http://www.openwall.com/lists/oss-security/2022/01/04/4
- http://www.openwall.com/lists/oss-security/2022/02/07/1
- https://www.openwall.com/lists/oss-security/2022/01/04/4
→ the Explorer · watch your stack · NVD