Vulnerability Description
Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Geronimo | 2.0.1 |
Related Weaknesses (CWE)
References
- http://geronimo.apache.org/2007/09/07/mejb-security-alert.html
- http://osvdb.org/38661
- http://secunia.com/advisories/26906Vendor Advisory
- http://secunia.com/advisories/27464
- http://www-1.ibm.com/support/docview.wss?uid=swg21271586
- http://www.securityfocus.com/bid/25804
- http://www.securitytracker.com/id?1018877
- https://issues.apache.org/jira/browse/GERONIMO-3456
- http://geronimo.apache.org/2007/09/07/mejb-security-alert.html
- http://osvdb.org/38661
- http://secunia.com/advisories/26906Vendor Advisory
- http://secunia.com/advisories/27464
- http://www-1.ibm.com/support/docview.wss?uid=swg21271586
- http://www.securityfocus.com/bid/25804
- http://www.securitytracker.com/id?1018877
FAQ
What is CVE-2007-5085?
CVE-2007-5085 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vector...
How severe is CVE-2007-5085?
CVE-2007-5085 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5085?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Geronimo.