CVE Vulnerabilities

CVE-2007-2849

Published: May 24, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check.

Affected Software

NameVendorStart VersionEnd Version
Knowledgetree_document_managementKnowledgetree_document_management3.3.3 (including)3.3.3 (including)
KnowledgetreeUbuntudapper*
KnowledgetreeUbuntuedgy*
KnowledgetreeUbuntufeisty*
KnowledgetreeUbuntugutsy*

References