vendor:
James
by:
y3dips
7.5
CVSS
HIGH
Denial-of-Service
400
CWE
Product Name: James
Affected Version From: 2.2.2000
Affected Version To: 2.2.2000
Patch Exists: YES
Related CWE: N/A
CPE: 2.2.2000
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2005
Apache James Remote Denial-of-Service Vulnerability
Apache James is prone to a remote denial-of-service vulnerability. This issue is due to the application's failure to efficiently handle malformed SMTP commands. This issue allows remote attackers to consume excessive CPU resources of affected computers, potentially denying service to legitimate users.
Mitigation:
Ensure that Apache James is up to date with the latest version.