Lucene search

K
prionPRIOn knowledge basePRION:CVE-2007-4548
HistoryAug 27, 2007 - 11:17 p.m.

Authentication flaw

2007-08-2723:17:00
PRIOn knowledge base
www.prio-n.com
3

8.1 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.4%

The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.

CPENameOperatorVersion
geronimoeq2.0

8.1 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.4%

Related for PRION:CVE-2007-4548