Vulnerability disclosed in Apache James 

Issue date: 04-04-2022
Affects versions: 14.7, 13.4, 12.6

Security Issue ID

SECURITY-289

 

Affected Product Version(s)

14.7.3, 13.4.14, 12.6.23 and previous releases.


Severity 

Low


Description

CVE-2021-38542

CVE-2021-40110 

CVE-2021-40111 

CVE-2021-40525 

The vulnerabilities above have been reported in Apache James. brXM uses the mime4j component of James, which is not implicated in any of the vulnerabilities. Therefore, we consider these reports to be false positives for the brXM product. Nonetheless, we have updated mime4j to a more recent maintenance version as part of the most recent set of maintenance updates for brXM.

Instructions

Customers are recommended to upgrade to the latest version. As of the time of writing, 14.7.5, 13.4.16, or 12.6.25.