CVE-2007-5797
published 2007-11-03CVE-2007-5797: SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass…
PriorityP345high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.15%
86.4th percentile
SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | geronimo | — | — |
| apache | geronimo | — | — |
| apache | geronimo | — | — |
| apache | geronimo | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7mfx-869f-5w95: SQLLoginModule in Apache Geronimo 2
ghsa_unreviewed·2022-05-01
CVE-2007-5797 [HIGH] CWE-287 GHSA-7mfx-869f-5w95: SQLLoginModule in Apache Geronimo 2
SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.
Red Hat
CVE-2007-5797: SQLLoginModule in Apache Geronimo 2
vendor_redhat·CVSS 7.5
CVE-2007-5797 [HIGH] CVE-2007-5797: SQLLoginModule in Apache Geronimo 2
SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.
Statement: Not vulnerable. This issue did not affect versions of geronimo-specs packages as shipped Red Hat Enterprise Linux 5, Red Hat Application Stack, Red Hat Application Server, Red Hat Directory Server and Red Hat Certificate System, as the geronimo-specs package only contains the specification of the Apache Geronimo Servers services and interfaces and not the vulnerable J2EE server classes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/38662http://secunia.com/advisories/27478http://secunia.com/advisories/27482http://www-1.ibm.com/support/docview.wss?uid=swg21286105http://www.securityfocus.com/bid/26287http://www.vupen.com/english/advisories/2007/3675http://www.vupen.com/english/advisories/2007/3676https://issues.apache.org/jira/browse/GERONIMO-3543http://osvdb.org/38662http://secunia.com/advisories/27478http://secunia.com/advisories/27482http://www-1.ibm.com/support/docview.wss?uid=swg21286105http://www.securityfocus.com/bid/26287http://www.vupen.com/english/advisories/2007/3675http://www.vupen.com/english/advisories/2007/3676https://issues.apache.org/jira/browse/GERONIMO-3543
2007-11-03
Published