CVE-2007-5797

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
03/11/2007
Last modified:
09/04/2025

Description

SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:geronimo:2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:geronimo:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:geronimo:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:geronimo:2.1:*:*:*:*:*:*:*