Security Advisory

CVE-2007-5797

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2007-11-03 00:00:00
Last updated 2024-08-07 15:46:59
Assigner mitre
State PUBLISHED

Description

SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.