Public advisories disclosed two critical pre-authentication remote code execution vulnerabilities in Xeams 10.3 build 6449 from Synametrics Technologies, both of which can reportedly deliver uid=0(root) on default deployments. One attack chain abuses the SMTP rules engine’s X-SM_SAVE_BODY_4DEBUGGING debug write behavior to place attacker-controlled files at arbitrary paths; when Xeams runs as root, the write primitive can be leveraged through cron to achieve unauthenticated root command execution.
A second flaw leaves SQLRunner.jsp exposed without authentication and combines that access with hardcoded Apache Derby credentials to let attackers run arbitrary SQL and write a JSP webshell to the server. The published reports said both exploit paths were verified end to end, giving attackers full control of the mail server and potential access to the Xeams mail repository, sharply increasing the risk of mailbox compromise, persistence, and broader server takeover.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A Full Disclosure post publicly circulated the advisory covering the two Xeams 10.3 build 6449 pre-authentication root RCE vulnerabilities. The repost highlighted that both attack chains had been verified end-to-end and could yield uid=0(root) in default deployments.
0day Rubbish Research Team publicly disclosed two critical vulnerabilities affecting Xeams 10.3 build 6449 from Synametrics Technologies. The advisories described one SMTP-based arbitrary file write to cron root RCE chain and one unauthenticated SQLRunner.jsp to Derby-backed JSP webshell root RCE chain, with proof-of-concept code and full analysis published.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open source0day-rubbish.com
Open source0day-rubbish.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.