Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-1469


CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes it easier for remote attackers to trick a user into disclosing credentials via CRLF sequences preceding a Reply-To header in the subject element of an XML document, as demonstrated by triggering an e-mail message from the server that contains a user's correct credentials, and requests that the user compose a reply that includes this message.


Security Impact Summary

CVE-2009-1469 is a security vulnerability that . Impacting 2 products from icewarp, from icewarp organizations running these solutions should prioritize assessment and patching.

Historical Context

Originally identified in 2009, this vulnerability predates many modern security frameworks and practices. The vulnerability landscape of that era was characterized by different threat models and less mature defense mechanisms compared to contemporary standards.


Published

2009-05-05T20:30:00.250

Last Modified

2026-04-23T00:35:47.467

Status

Modified

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application icewarp email_server ≤ 9.3.0 Yes
Application icewarp email_server 2.10.105 Yes
Application icewarp email_server 2.10.110 Yes
Application icewarp email_server 2.10.115 Yes
Application icewarp email_server 2.10.140 Yes
Application icewarp email_server 2.10.150 Yes
Application icewarp email_server 2.10.165 Yes
Application icewarp email_server 2.10.170 Yes
Application icewarp email_server 2.10.190 Yes
Application icewarp email_server 2.10.200 Yes
Application icewarp email_server 2.10.210 Yes
Application icewarp email_server 2.10.220 Yes
Application icewarp email_server 2.10.240 Yes
Application icewarp email_server 2.10.250 Yes
Application icewarp email_server 2.10.260 Yes
Application icewarp email_server 2.10.280 Yes
Application icewarp email_server 2.10.290 Yes
Application icewarp email_server 2.10.310 Yes
Application icewarp email_server 2.10.320 Yes
Application icewarp email_server 2.10.330 Yes
Application icewarp email_server 2.10.331 Yes
Application icewarp email_server 2.10.340 Yes
Application icewarp email_server 2.10.350 Yes
Application icewarp email_server 2.10.360 Yes
Application icewarp email_server 3.00.100 Yes
Application icewarp email_server 3.00.110 Yes
Application icewarp email_server 3.00.120 Yes
Application icewarp email_server 3.00.130 Yes
Application icewarp email_server 3.00.140 Yes
Application icewarp email_server 3.10.011 Yes
Application icewarp email_server 3.10.110 Yes
Application icewarp email_server 4.00.30 Yes
Application icewarp email_server 4.2.1 Yes
Application icewarp email_server 4.2.2 Yes
Application icewarp email_server 4.2.3 Yes
Application icewarp email_server 4.4.1 Yes
Application icewarp email_server 4.4.2 Yes
Application icewarp email_server 4.10.040 Yes
Application icewarp email_server 4.10.050 Yes
Application icewarp email_server 5.1.2 Yes
Application icewarp email_server 5.1.3 Yes
Application icewarp email_server 5.1.5 Yes
Application icewarp email_server 5.3.0 Yes
Application icewarp email_server 5.3.2 Yes
Application icewarp email_server 5.4.1 Yes
Application icewarp email_server 5.4.2 Yes
Application icewarp email_server 5.4.3 Yes
Application icewarp email_server 5.4.4 Yes
Application icewarp email_server 5.5.3 Yes
Application icewarp email_server 5.5.4 Yes
Application icewarp email_server 5.5.5 Yes
Application icewarp email_server 5.5.6 Yes
Application icewarp email_server 5.5.7 Yes
Application icewarp email_server 5.7.3 Yes
Application icewarp email_server 5.8.2 Yes
Application icewarp email_server 5.8.3 Yes
Application icewarp email_server 5.8.4 Yes
Application icewarp email_server 5.8.5 Yes
Application icewarp email_server 5.8.6 Yes
Application icewarp email_server 5.9.4 Yes
Application icewarp email_server 6.0.2 Yes
Application icewarp email_server 6.0.3 Yes
Application icewarp email_server 6.0.5 Yes
Application icewarp email_server 6.0.7 Yes
Application icewarp email_server 6.1.0 Yes
Application icewarp email_server 6.2.1 Yes
Application icewarp email_server 7.0.1 Yes
Application icewarp email_server 7.1.4 Yes
Application icewarp email_server 7.1.6 Yes
Application icewarp email_server 7.2.0 Yes
Application icewarp email_server 7.4.0 Yes
Application icewarp email_server 7.4.2 Yes
Application icewarp email_server 7.4.5 Yes
Application icewarp email_server 7.5.2 Yes
Application icewarp email_server 7.6.0 Yes
Application icewarp email_server 7.6.4 Yes
Application icewarp email_server 8.0.1 Yes
Application icewarp email_server 8.0.2 Yes
Application icewarp email_server 8.0.3 Yes
Application icewarp email_server 8.2.0 Yes
Application icewarp email_server 8.2.2 Yes
Application icewarp email_server 8.3.5 Yes
Application icewarp email_server 8.3.8 Yes
Application icewarp email_server 8.5.0 Yes
Application icewarp email_server 8.9.1 Yes
Application icewarp email_server 9.0.0 Yes
Application icewarp email_server 9.1.0 Yes
Application icewarp email_server 9.2.0 Yes
Application icewarp webmail_server ≤ 9.3.0 Yes
Application icewarp webmail_server 2.10.105 Yes
Application icewarp webmail_server 2.10.110 Yes
Application icewarp webmail_server 2.10.115 Yes
Application icewarp webmail_server 2.10.140 Yes
Application icewarp webmail_server 2.10.150 Yes
Application icewarp webmail_server 2.10.165 Yes
Application icewarp webmail_server 2.10.170 Yes
Application icewarp webmail_server 2.10.190 Yes
Application icewarp webmail_server 2.10.200 Yes
Application icewarp webmail_server 2.10.210 Yes
Application icewarp webmail_server 2.10.220 Yes
Application icewarp webmail_server 2.10.240 Yes
Application icewarp webmail_server 2.10.250 Yes
Application icewarp webmail_server 2.10.260 Yes
Application icewarp webmail_server 2.10.280 Yes
Application icewarp webmail_server 2.10.290 Yes
Application icewarp webmail_server 2.10.310 Yes
Application icewarp webmail_server 2.10.320 Yes
Application icewarp webmail_server 2.10.330 Yes
Application icewarp webmail_server 2.10.331 Yes
Application icewarp webmail_server 2.10.340 Yes
Application icewarp webmail_server 2.10.350 Yes
Application icewarp webmail_server 2.10.360 Yes
Application icewarp webmail_server 3.00.100 Yes
Application icewarp webmail_server 3.00.110 Yes
Application icewarp webmail_server 3.00.120 Yes
Application icewarp webmail_server 3.00.130 Yes
Application icewarp webmail_server 3.00.140 Yes
Application icewarp webmail_server 3.10.011 Yes
Application icewarp webmail_server 3.10.110 Yes
Application icewarp webmail_server 4.00.30 Yes
Application icewarp webmail_server 4.2.1 Yes
Application icewarp webmail_server 4.2.2 Yes
Application icewarp webmail_server 4.2.3 Yes
Application icewarp webmail_server 4.4.1 Yes
Application icewarp webmail_server 4.4.2 Yes
Application icewarp webmail_server 4.10.040 Yes
Application icewarp webmail_server 4.10.050 Yes
Application icewarp webmail_server 5.1.2 Yes
Application icewarp webmail_server 5.1.3 Yes
Application icewarp webmail_server 5.1.5 Yes
Application icewarp webmail_server 5.3.0 Yes
Application icewarp webmail_server 5.3.2 Yes
Application icewarp webmail_server 5.4.1 Yes
Application icewarp webmail_server 5.4.2 Yes
Application icewarp webmail_server 5.4.3 Yes
Application icewarp webmail_server 5.4.4 Yes
Application icewarp webmail_server 5.5.3 Yes
Application icewarp webmail_server 5.5.4 Yes
Application icewarp webmail_server 5.5.5 Yes
Application icewarp webmail_server 5.5.6 Yes
Application icewarp webmail_server 5.5.7 Yes
Application icewarp webmail_server 5.7.3 Yes
Application icewarp webmail_server 5.8.2 Yes
Application icewarp webmail_server 5.8.3 Yes
Application icewarp webmail_server 5.8.4 Yes
Application icewarp webmail_server 5.8.5 Yes
Application icewarp webmail_server 5.8.6 Yes
Application icewarp webmail_server 5.9.4 Yes
Application icewarp webmail_server 6.0.2 Yes
Application icewarp webmail_server 6.0.3 Yes
Application icewarp webmail_server 6.0.5 Yes
Application icewarp webmail_server 6.0.7 Yes
Application icewarp webmail_server 6.1.0 Yes
Application icewarp webmail_server 6.2.1 Yes
Application icewarp webmail_server 7.0.1 Yes
Application icewarp webmail_server 7.1.4 Yes
Application icewarp webmail_server 7.1.6 Yes
Application icewarp webmail_server 7.2.0 Yes
Application icewarp webmail_server 7.4.0 Yes
Application icewarp webmail_server 7.4.2 Yes
Application icewarp webmail_server 7.4.5 Yes
Application icewarp webmail_server 7.5.2 Yes
Application icewarp webmail_server 7.6.0 Yes
Application icewarp webmail_server 7.6.4 Yes
Application icewarp webmail_server 8.0.1 Yes
Application icewarp webmail_server 8.0.2 Yes
Application icewarp webmail_server 8.0.3 Yes
Application icewarp webmail_server 8.2.0 Yes
Application icewarp webmail_server 8.2.2 Yes
Application icewarp webmail_server 8.3.5 Yes
Application icewarp webmail_server 8.3.8 Yes
Application icewarp webmail_server 8.5.0 Yes
Application icewarp webmail_server 8.9.1 Yes
Application icewarp webmail_server 9.0.0 Yes
Application icewarp webmail_server 9.1.0 Yes
Application icewarp webmail_server 9.2.0 Yes

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For icewarp's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.