CVE-2007-2849
Estado: ModificadaAlta (10)—
KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.71%
- Percentil entre todas las CVEs puntuadas: 86
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://osvdb.org/36578
- http://secunia.com/advisories/25360
- http://sourceforge.net/forum/forum.php?forum_id=698243
- http://sourceforge.net/project/shownotes.php?release_id=510338
- http://www.securityfocus.com/bid/24110
- http://www.vupen.com/english/advisories/2007/1920
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34463
- http://osvdb.org/36578
- http://secunia.com/advisories/25360
- http://sourceforge.net/forum/forum.php?forum_id=698243
- http://sourceforge.net/project/shownotes.php?release_id=510338
- http://www.securityfocus.com/bid/24110
- http://www.vupen.com/english/advisories/2007/1920
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34463
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-2849",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-05-24T18:30:00.000",
"references": [
{
"url": "http://osvdb.org/36578",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/25360",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://sourceforge.net/forum/forum.php?forum_id=698243",
"source": "cve@mitre.org"
},
{
"url": "http://sourceforge.net/project/shownotes.php?release_id=510338",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/24110",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/1920",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34463",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/36578",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/25360",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://sourceforge.net/forum/forum.php?forum_id=698243",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://sourceforge.net/project/shownotes.php?release_id=510338",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/24110",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/1920",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34463",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check."
},
{
"lang": "es",
"value": "El Administrador de Documentos KnowledgeTree (también conocido como KnowledgeTree Open Source) anterior al STABLE 3.3.7 no requiere contraseña para usuarios no registrados, cuando el usuario existe en el Active Directory, lo que permite a atacantes remotos validarse en el KTDMS sin tener un control de autorización intencionado."
}
],
"lastModified": "2026-06-16T22:40:33.323",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:knowledgetree_document_management:knowledgetree_document_management:3.3.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4EFCB854-7EDE-4D1C-B5F5-8C6EE6DAFE89"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}