Unspecified vulnerability in Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to execute arbitrary Python code via vectors involving the ZEO network protocol.
2009-08-07T19:30:00.203
2025-04-09T00:30:58.490
Deferred
CVSSv2: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | zope | zodb | ≤ 3.8.1 | Yes |
| Application | zope | zodb | 2.8.11 | Yes |
| Application | zope | zodb | 2.9.11 | Yes |
| Application | zope | zodb | 2.10.9 | Yes |
| Application | zope | zodb | 2.11.4 | Yes |
| Application | zope | zodb | 3.1 | Yes |
| Application | zope | zodb | 3.1.1 | Yes |
| Application | zope | zodb | 3.2 | Yes |
| Application | zope | zodb | 3.2.4 | Yes |
| Application | zope | zodb | 3.3 | Yes |
| Application | zope | zodb | 3.3.3 | Yes |
| Application | zope | zodb | 3.4 | Yes |
| Application | zope | zodb | 3.4.1 | Yes |
| Application | zope | zodb | 3.5 | Yes |
| Application | zope | zodb | 3.6 | Yes |
| Application | zope | zodb | 3.7 | Yes |
| Application | zope | zodb | 3.8.0 | Yes |