AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2007-4364

HIGH · CVSS 8.5 EPSS 2.83%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-08-15 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2007-4364
Severity
HIGH
CVSS
8.5
EPSS
2.83%
Java

Original NVD Description

Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory Interface (JNDI), related to (1) a nonexistent account name in combination with an empty password, which allows remote attackers to trigger a certain "unexpected / strange response" from an LDAP server, and (2) a reauthentication attempt that throws an exception, which allows remote attackers to trigger use of a cached authentication decision. NOTE: authentication can be bypassed by using vector 1 followed by vector 2, and possibly can be bypassed by using a single vector.