CVE-2007-4548
Estado: ModificadaAlta (10)—
The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 4.19%
- Percentil entre todas las CVEs puntuadas: 91
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
Referencias
- http://geronimo.apache.org/2007/08/13/apache-geronimo-v20-release-delayed-due-to-security-issue.html
- http://geronimo.apache.org/2007/08/21/apache-geronimo-201-released.html
- http://www.nabble.com/Geronimo-2.0-Release-suspended-due-to-security-issue-found-before-release-t4263667s134.html
- https://issues.apache.org/jira/browse/GERONIMO-1201
- https://issues.apache.org/jira/browse/GERONIMO-3404
- http://geronimo.apache.org/2007/08/13/apache-geronimo-v20-release-delayed-due-to-security-issue.html
- http://geronimo.apache.org/2007/08/21/apache-geronimo-201-released.html
- http://www.nabble.com/Geronimo-2.0-Release-suspended-due-to-security-issue-found-before-release-t4263667s134.html
- https://issues.apache.org/jira/browse/GERONIMO-1201
- https://issues.apache.org/jira/browse/GERONIMO-3404
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-4548",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-08-27T23:17:00.000",
"references": [
{
"url": "http://geronimo.apache.org/2007/08/13/apache-geronimo-v20-release-delayed-due-to-security-issue.html",
"source": "cve@mitre.org"
},
{
"url": "http://geronimo.apache.org/2007/08/21/apache-geronimo-201-released.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.nabble.com/Geronimo-2.0-Release-suspended-due-to-security-issue-found-before-release-t4263667s134.html",
"source": "cve@mitre.org"
},
{
"url": "https://issues.apache.org/jira/browse/GERONIMO-1201",
"source": "cve@mitre.org"
},
{
"url": "https://issues.apache.org/jira/browse/GERONIMO-3404",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://geronimo.apache.org/2007/08/13/apache-geronimo-v20-release-delayed-due-to-security-issue.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://geronimo.apache.org/2007/08/21/apache-geronimo-201-released.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.nabble.com/Geronimo-2.0-Release-suspended-due-to-security-issue-found-before-release-t4263667s134.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://issues.apache.org/jira/browse/GERONIMO-1201",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://issues.apache.org/jira/browse/GERONIMO-3404",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module."
},
{
"lang": "es",
"value": "El método de entrada en las implementaciones LoginModule en Apache Geronimo 2.0 no pasa por FailedLoginException para las entradas fallidas, lo cual permite a atacantes remotos evitar los requisitios de validación, utilización de módulos de su elección, y conseguir acceso con privilegios administrativos a través del envío de un nombre de usuario en blanco y contraseñas con el desplegador de línea de comando en el módulo del despliegue."
}
],
"lastModified": "2026-06-16T22:44:18.287",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:geronimo:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA6E27E4-BE63-4AE3-B29C-6BCF752FF608"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}