Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2011-5034

Disclosure Date: December 30, 2011 (last updated October 04, 2023)
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.
0
Attacker Value
Unknown

CVE-2007-5797

Disclosure Date: November 03, 2007 (last updated October 04, 2023)
SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.
0
Attacker Value
Unknown

CVE-2007-5085

Disclosure Date: September 26, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-4548

Disclosure Date: August 27, 2007 (last updated October 04, 2023)
The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.
0