Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain privileges via brute force username and password guessing.
References
Link | Resource |
---|---|
http://www.iss.net/security_center/static/9688.php | Vendor Advisory |
http://archives.neohapsis.com/archives/bugtraq/2002-07/0329.html |
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-10-03 21:00
Updated : 2008-09-05 13:29
NVD link : CVE-2002-1065
Mitre link : CVE-2002-1065
JSON object : View
CWE
Products Affected
t._hauck
- jana_web_server