{"id":"CVE-2017-12628","details":"The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only on local-host, this vulnerability can only be used for privilege escalation. Release 3.0.1 upgrades the incriminated library.","aliases":["GHSA-xj7q-q94c-6wr3"],"modified":"2026-07-08T11:49:33.004693Z","published":"2017-10-20T15:29:00.283Z","references":[{"type":"WEB","url":"https://www.mail-archive.com/server-user%40james.apache.org/msg15633.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/101532"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/james-project","events":[{"introduced":"0"},{"last_affected":"d2cf67bc17189ec95e314b28af93974d296db9af"}],"database_specific":{"cpe":"cpe:2.3:a:apache:james_server:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.0.0"}],"source":"CPE_RANGE"}}],"versions":["james-project-3.0.0","james-project-3.0.0-RC1","james-project-3.0.0-beta5","james-project-3.0-beta5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-12628.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}