5
CVSSv2

CVE-2014-7807

Published: 10/12/2014 Updated: 09/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Apache CloudStack 4.3.x prior to 4.3.2 and 4.4.x prior to 4.4.2 allows remote malicious users to bypass authentication via a login request without a password, which triggers an unauthenticated bind.

Vulnerable Product Search on Vulmon Subscribe to Product

apache cloudstack 4.3.0

apache cloudstack 4.3.1

apache cloudstack 4.4.0

apache cloudstack 4.4.1