Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" via unspecified vectors.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/25804 | vdb entry |
http://geronimo.apache.org/2007/09/07/mejb-security-alert.html | |
http://secunia.com/advisories/27464 | third party advisory |
http://www-1.ibm.com/support/docview.wss?uid=swg21271586 | |
http://www.securitytracker.com/id?1018877 | vdb entry |
https://issues.apache.org/jira/browse/GERONIMO-3456 | |
http://secunia.com/advisories/26906 | third party advisory vendor advisory |
http://osvdb.org/38661 | vdb entry |