Skip to content

[FP]: False positive findings in Dependency Checker for angus-activation.jar #8211

@ashu4

Description

@ashu4

Package URl

pkg:maven/org.eclipse.angus/[email protected]

CPE

cpe:2.3:a:eclipse:angus_mail:2.0.2:::::::*

CVE

CVE-2025-7962

ODC Integration

{"label" => "Docker"}

ODC Version

12.1.9

Description

Hi Team,

We are getting following CVE in Dependency Checker Tool findings, although as per our analysis we consider this as false positive.
CVE details and our justification for false positive for CVE is mentioned below.
Kindly check and get it fixed in Dependency Checker tool. So this false positive does not appear in scan report.

CVE-2025-7962
Justification: This vulnerability is related to Jakarta/Angus Mail.
Product includes angus-activation.jar only although vulnerability is in the SMTP/mail component (Jakarta Mail/Angus Mail,), not in the activation library. Scanner is falsely identifying this vulnerability on angus-activation.jar. Hence considering it as false positive.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions