CVE-2002-1065
Summary
| CVE | CVE-2002-1065 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-10-04 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain privileges via brute force username and password guessing. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | T. Hauck | Jana Web Server | 1.0 | All | All | All |
| Application | T. Hauck | Jana Web Server | 1.45 | All | All | All |
| Application | T. Hauck | Jana Web Server | 1.46 | All | All | All |
| Application | T. Hauck | Jana Web Server | 2.0 | All | All | All |
| Application | T. Hauck | Jana Web Server | 2.0_beta1 | All | All | All |
| Application | T. Hauck | Jana Web Server | 2.0_beta2 | All | All | All |
| Application | T. Hauck | Jana Web Server | 2.2.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Neohapsis Archives - Bugtraq - SECURITY.NNOV: multiple vulnerabilities in JanaServer - From 3APA3A_at_SECURITY.NNOV.RU | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| ISS X-Force Database: jana-pop3-bruteforce (9688): Jana Server POP3 username/password brute force | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.