Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2) user parameter to services/usermanager/users/.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Http Apache Jetspeed | — | Upgrade Apache Jetspeed-2 to version 2.3.1 or later, which is the final release of the project and contains the fixes for the 2016 security advisories. Note that Apache Jetspeed-2 has been declared dormant (2022) and retired to the Apache Attic (2025), so 2.3.1 is the highest version that will ever ship; migration to a supported portal framework should be considered. | Jun 12, 2026 | Apr 11, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub