CVE-2025-49656

Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue.
References
Link Resource
https://lists.apache.org/thread/qmm21som8zct813vx6dfd1phnfro6mwq Vendor Advisory Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:jena:*:*:*:*:*:*:*:*

History

29 Jul 2025, 15:04

Type Values Removed Values Added
CPE cpe:2.3:a:apache:jena:*:*:*:*:*:*:*:*
Summary
  • (es) Los usuarios con acceso de administrador pueden crear archivos de bases de datos fuera del área de archivos del servidor Fuseki. Este problema afecta a Apache Jena hasta la versión 5.4.0. Se recomienda actualizar a la versión 5.5.0, que soluciona el problema.
First Time Apache jena
Apache
References () https://lists.apache.org/thread/qmm21som8zct813vx6dfd1phnfro6mwq - () https://lists.apache.org/thread/qmm21som8zct813vx6dfd1phnfro6mwq - Vendor Advisory, Issue Tracking

21 Jul 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

21 Jul 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 10:15

Updated : 2025-07-29 15:04


NVD link : CVE-2025-49656

Mitre link : CVE-2025-49656

CVE.ORG link : CVE-2025-49656


JSON object : View

Products Affected

apache

  • jena
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')