Users with administrator access can create databases files outside the files area of the Fuseki server.
This issue affects Apache Jena version up to 5.4.0.
Users are recommended to upgrade to version 5.5.0, which fixes the issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/qmm21som8zct813vx6dfd1phnfro6mwq | Issue Tracking Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/07/21/1 |
Configurations
History
04 Nov 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | () https://lists.apache.org/thread/qmm21som8zct813vx6dfd1phnfro6mwq - Issue Tracking, Vendor Advisory |
29 Jul 2025, 15:04
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Apache
Apache jena |
|
| CPE | cpe:2.3:a:apache:jena:*:*:*:*:*:*:*:* | |
| References | () https://lists.apache.org/thread/qmm21som8zct813vx6dfd1phnfro6mwq - Vendor Advisory, Issue Tracking | |
| Summary |
|
21 Jul 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
21 Jul 2025, 10:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-07-21 10:15
Updated : 2025-11-04 22:16
NVD link : CVE-2025-49656
Mitre link : CVE-2025-49656
CVE.ORG link : CVE-2025-49656
JSON object : View
Products Affected
apache
- jena
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
