Vulnerability Details CVE-2021-38542
Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 49.2%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
Products affected by CVE-2021-38542
-
-
cpe:2.3:a:apache:james:2.2.0
-
cpe:2.3:a:apache:james:3.3.0
-
cpe:2.3:a:apache:james:3.4.0