Apache James server version 3.7.3... CVE-2023-26269

- AV AC AU C I A
发布: 2023-04-03
修订: 2023-04-18

Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user. Administrators are advised to disable JMX, or set up a JMX password. Note that version 3.7.4 onward will set up a JMX password automatically for Guice users.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息