Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-2701


Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors.


Published

2009-09-08T18:30:00.233

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.8

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zope zodb 3.8 Yes
Application zope zodb 3.8.0 Yes
Application zope zodb 3.8.1 Yes
Application zope zodb 3.8.2 Yes
Application zope zodb 3.9.0 Yes
Application zope zodb 3.9.0b1 Yes
Application zope zodb 3.9.0b2 Yes
Application zope zodb 3.9.0b3 Yes
Application zope zodb 3.9.0b4 Yes
Application zope zodb 3.9.0b5 Yes
Application zope zodb 3.9.0c1 Yes

References