← back
CVE-2025-49656highCWE-22

Apache Jena: Administrative users can create files outside the server directory space via the admin UI

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 1.5%
exploitation probability
1.5%top 28% of all CVEs
observed exploitation
nono source reports it
Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N