6

CVE-2009-2701

Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zope ≫ Zodb Version 3.8
Zope ≫ Zodb Version 3.8.0
Zope ≫ Zodb Version 3.8.1
Zope ≫ Zodb Version 3.8.2
Zope ≫ Zodb Version 3.9.0
Zope ≫ Zodb Version 3.9.0b1
Zope ≫ Zodb Version 3.9.0b2
Zope ≫ Zodb Version 3.9.0b3
Zope ≫ Zodb Version 3.9.0b4
Zope ≫ Zodb Version 3.9.0b5
Zope ≫ Zodb Version 3.9.0c1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.97% 0.573
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://pypi.python.org/pypi/ZODB3/3.8.3
Patch
http://pypi.python.org/pypi/ZODB3/3.9.0c2
Patch
http://www.vupen.com/english/advisories/2009/2534
Patch
Vendor Advisory
https://mail.zope.org/pipermail/zope-announce/2009-September/002221.html
Patch