Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-4548

Опубликовано: 27 авг. 2007
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:geronimo:2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.01011
Низкий

10 Critical

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
почти 4 года назад

The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.

EPSS

Процентиль: 77%
0.01011
Низкий

10 Critical

CVSS2

Дефекты

CWE-287