CVE Vulnerabilities

CVE-2002-1065

Published: Oct 04, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain privileges via brute force username and password guessing.

Affected Software

NameVendorStart VersionEnd Version
Jana_web_serverT._hauck1.0 (including)1.0 (including)
Jana_web_serverT._hauck1.45 (including)1.45 (including)
Jana_web_serverT._hauck1.46 (including)1.46 (including)
Jana_web_serverT._hauck2.0 (including)2.0 (including)
Jana_web_serverT._hauck2.0_beta1 (including)2.0_beta1 (including)
Jana_web_serverT._hauck2.0_beta2 (including)2.0_beta2 (including)
Jana_web_serverT._hauck2.2.1 (including)2.2.1 (including)

References