Vulnerabilities > Apache > Geronimo > 2.0

DATE CVE VULNERABILITY TITLE RISK
2007-11-03 CVE-2007-5797 Improper Authentication vulnerability in Apache Geronimo
SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.
network
low complexity
apache CWE-287
7.5
2007-08-27 CVE-2007-4548 Improper Authentication vulnerability in Apache Geronimo 2.0
The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.
network
low complexity
apache CWE-287
critical
10.0