Apache Jena: Administrative users can create files outside the server directory space via the admin UI
Vulnerability Description
Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-49656
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Noriaki Iwasaki; Cyber Defense Institute, Inc
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →