CVE Vulnerabilities

CVE-2007-2849

Published: May 24, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check.

Affected Software

Name Vendor Start Version End Version
Knowledgetree_document_management Knowledgetree_document_management 3.3.3 (including) 3.3.3 (including)
Knowledgetree Ubuntu dapper *
Knowledgetree Ubuntu edgy *
Knowledgetree Ubuntu feisty *
Knowledgetree Ubuntu gutsy *

References