CVE-2017-12628: Apache James Server

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only on local-host, this vulnerability can only be used for privilege escalation. Release 3.0.1 upgrades the incriminated library.

Affected products

  • Apache James Server: up to and including 3.0.0

Published 2017-10-20. Last modified 2026-06-17.