PT-2007-6763 · Apache · Apache Geronimo

Jarek Gawor

·

Publicado

2007-11-03

·

Atualizado

2011-03-08

·

CVE-2007-5797

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Geronimo versions 2.0 through 2.1
Description The issue allows remote attackers to bypass authentication by attempting to log in with any username not contained in the database, as the SQLLoginModule does not throw an exception for a nonexistent username.
Recommendations For Apache Geronimo versions 2.0 through 2.1, consider temporarily restricting access to the SQLLoginModule until a patch is available. As a workaround, monitor login attempts closely to detect and prevent potential unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5797

Produtos afetados

Apache Geronimo