In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.
CVSS Details
- CVSS 4.0 Base Score: 6 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | Oct 23, 2025 | Oct 21, 2025 |
| Debian | — | No solution exists | Jul 23, 2025 | Jul 21, 2025 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Dec 3, 2025 | Jul 21, 2025 |
| Oracle Missing Cpu Jul 2026 | — | Apply the July 2026 Critical Patch Update (CPU) for Oracle Database | Jul 22, 2026 | Jul 22, 2026 |
| Red Hat Jboss Eap | — | — | Aug 15, 2025 | Jul 21, 2025 |
| Suse | — | Upgrade javamailUpgrade javamail-javadoc | Dec 5, 2025 | Aug 29, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub