CVE-2015-7611: Apache James Server

High severity, CVSS 8.1. EPSS: 68.6% chance of exploitation in the next 30 days.

Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified vectors.

Affected products

  • Apache James Server: version 2.3.2 only

Published 2016-06-07. Last modified 2026-06-17.