Apache Jena
cpe:2.3:a:apache:jena:*:*:*:*:*:*:*
- <= 5.4.0
A vulnerability exists in Apache Jena in versions prior to 5.4.0, where file access paths in configuration files uploaded by users with administrator rights are not properly validated. This lack of validation could potentially be exploited to upload arbitrary configuration files. Users are advised to upgrade to version 5.5.0, which addresses this issue by disallowing arbitrary configuration uploads.
Exploitation of this vulnerability could lead to unauthorized configuration changes or the introduction of malicious configurations that could be executed by the application.
Users should upgrade to Apache Jena version 5.5.0 or later, which does not permit arbitrary configuration file uploads.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.