Beveiligingsadvies

CVE-2007-5797

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2007-11-03 00:00:00
Laatst bijgewerkt 2024-08-07 15:46:59
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.