cbcvebase.
CVE-2007-4548
published 2007-08-27

CVE-2007-4548: The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to…

PriorityP356critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.19%
89.8th percentile
The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.

Affected

1 ranges
VendorProductVersion rangeFixed in
apachegeronimo
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.