Apache Jena: Administrative users can create files outside the server directory space via the admin UI
Published Jul 21, 2025
7.5
HIGHCVSS 3.1
EPSS 1.45%
Description
Users with administrator access can create databases files outside the files area of the Fuseki server.
This issue affects Apache Jena version up to 5.4.0.
Users are recommended to upgrade to version 5.5.0, which fixes the issue.
Affected products
-
- Version 0StatusaffectedConstraints<=5.4.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Jena | unaffected |
|
No data.
Red Hat AMQ Clients
jena-arq
Fix deferred
Red Hat Data Grid 8
jena-arq
Fix deferred
Red Hat JBoss Enterprise Application Platform 7
jena-arq
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
jena-arq
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
jena-arq
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AMQ Clients | jena-arq | Fix deferred | n/a |
| Red Hat Data Grid 8 | jena-arq | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jena-arq | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | jena-arq | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jena-arq | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (11)
- http://www.openwall.com/lists/oss-security/2025/07/21/1
- https://access.redhat.com/security/cve/CVE-2025-49656 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2382277 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-22076 Advisory
- https://github.com/advisories/GHSA-jq2c-m8gg-mqcm Advisory
- https://github.com/apache/jena/commit/03c5265910aa3a27907bf54f6b4aaae3409afa4f
- https://github.com/apache/jena/commit/35350569b4c1fd432d92e7c92af9597c4400debe
- https://github.com/apache/jena/issues/3212
- https://lists.apache.org/thread/qmm21som8zct813vx6dfd1phnfro6mwq vendor-advisoryIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-49656
- https://www.cve.org/CVERecord?id=CVE-2025-49656
Change history (0)
No recorded changes yet.