Apache James
cpe:2.3:a:apache:james_server:*:*:*:*:*:*:*
- <= 3.7.5
- >= 3.8.0, <= 3.8.1
A denial-of-service vulnerability has been identified in Apache James versions prior to 3.7.6 and 3.8.0 through 3.8.1. This vulnerability allows both authenticated and unauthenticated users to abuse IMAP literals, leading to unbounded memory allocation and prolonged computations. Versions 3.7.6 and 3.8.2 have addressed this issue by restricting improper use of IMAP literals.
Exploitation of this vulnerability can cause excessive memory usage and extended processing times, potentially leading to service degradation or unavailability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.