PT-2007-6763 · Apache · Apache Geronimo

Jarek Gawor

·

Published

2007-11-03

·

Updated

2011-03-08

·

CVE-2007-5797

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Geronimo versions 2.0 through 2.1
Description The issue allows remote attackers to bypass authentication by attempting to log in with any username not contained in the database, as the SQLLoginModule does not throw an exception for a nonexistent username.
Recommendations For Apache Geronimo versions 2.0 through 2.1, consider temporarily restricting access to the SQLLoginModule until a patch is available. As a workaround, monitor login attempts closely to detect and prevent potential unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5797

Affected Products

Apache Geronimo