Skip to main content

Vendor/product archive

apache / geronimo CVEs

Beta · best-effort

11 CVEs tagged to apache / geronimo3 Critical, 3 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2011-5034

Published Dec 30, 2011

Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0039

Published Apr 17, 2009

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hija…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0038

Published Apr 17, 2009

Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5518

Published Apr 17, 2009

Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0732

Published Feb 12, 2008

The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or direct…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5797

Published Nov 3, 2007

SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attemp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5085

Published Sep 26, 2007

Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to Geronimo internals" v…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4548

Published Aug 27, 2007

The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authenticatio…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-0254

Published Jan 18, 2006

Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1