← volver
CVE-2021-38542CWE-77

Apache James vulnerable to STARTTLS command injection (IMAP and POP3)

3Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackepss 2.3%
probabilidad de explotación
2.3%top 17% de las CVE
explotación observada
noninguna fuente lo reporta
Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information.