7.5
CVSSv2

CVE-2007-5797

Published: 03/11/2007 Updated: 08/03/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQLLoginModule in Apache Geronimo 2.0 up to and including 2.1 does not throw an exception for a nonexistent username, which allows remote malicious users to bypass authentication via a login attempt with any username not contained in the database.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache geronimo 2.0

apache geronimo 2.0.1

apache geronimo 2.0.2

apache geronimo 2.1