6

CVE-2009-2701

Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors.

Data is provided by the National Vulnerability Database (NVD)
ZopeZodb Version3.8
ZopeZodb Version3.8.0
ZopeZodb Version3.8.1
ZopeZodb Version3.8.2
ZopeZodb Version3.9.0
ZopeZodb Version3.9.0b1
ZopeZodb Version3.9.0b2
ZopeZodb Version3.9.0b3
ZopeZodb Version3.9.0b4
ZopeZodb Version3.9.0b5
ZopeZodb Version3.9.0c1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.42% 0.589
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P