← Back

CVE-2007-4548

nvd nist
Published: Aug 27, 2007Modified: Apr 23, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.

Affected (1)

Products: Apache: Geronimo
1 product
Geronimo
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.0

Timeline

No history available yet.