Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue.
History

Tue, 29 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:jena:*:*:*:*:*:*:*:*

Tue, 29 Jul 2025 12:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 22 Jul 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache jena
Vendors & Products Apache
Apache jena

Mon, 21 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Jul 2025 09:45:00 +0000

Type Values Removed Values Added
Description Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue.
Title Apache Jena: Administrative users can create files outside the server directory space via the admin UI
Weaknesses CWE-22
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-07-21T09:30:32.715Z

Updated: 2025-07-21T14:47:08.462Z

Reserved: 2025-06-09T16:47:05.868Z

Link: CVE-2025-49656

cve-icon Vulnrichment

Updated: 2025-07-21T14:46:43.521Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-21T10:15:25.440

Modified: 2025-07-29T15:04:20.553

Link: CVE-2025-49656

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-07-21T09:30:32Z

Links: CVE-2025-49656 - Bugzilla