Vulnerability Name: | CVE-2009-0669 (CCN-52379) | ||||||||||||||||||||||||||||
Assigned: | 2009-08-06 | ||||||||||||||||||||||||||||
Published: | 2009-08-06 | ||||||||||||||||||||||||||||
Updated: | 2017-08-17 | ||||||||||||||||||||||||||||
Summary: | Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass authentication via vectors involving the ZEO network protocol. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-287 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2009-0669 Source: CCN Type: Zope-Annce Mailing List, Thu Aug 6 08:01:09 EDT 2009 CVE-2009-0668 and CVE-2009-0669: Releases to fix ZODB ZEO server vulnerabilities Source: MLIST Type: UNKNOWN [zope-announce] 20090806 CVE-2009-0668 and CVE-2009-0669: Releases to fix ZODB ZEO server vulnerabilities Source: OSVDB Type: UNKNOWN 56826 Source: CCN Type: Python Web site Python Package Index : ZODB3 3.8.2 Source: CONFIRM Type: Patch, Vendor Advisory http://pypi.python.org/pypi/ZODB3/3.8.2#whats-new-in-zodb-3-8-2 Source: CCN Type: SA36204 Zope Object Database Two Vulnerabilities Source: SECUNIA Type: Vendor Advisory 36204 Source: CCN Type: SA36205 Zope ZODB Two Vulnerabilities Source: SECUNIA Type: Vendor Advisory 36205 Source: DEBIAN Type: DSA-1863 zope2.10/zope2.9 -- several vulnerabilities Source: DEBIAN Type: DSA-2234 zodb -- several vulnerabilities Source: CCN Type: OSVDB ID: 56826 Zope Object Database (ZODB) ZEO Storage Server Unspecified Authentication Bypass Source: BID Type: UNKNOWN 35987 Source: CCN Type: BID-35987 Zope Object Database ZEO Network Protocol Multiple Security Vulnerabilities Source: CCN Type: USN-848-1 Zope vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2009-2217 Source: CCN Type: Zope Web site Zope Source: XF Type: UNKNOWN zope-protocol-auth-bypass(52379) Source: XF Type: UNKNOWN zope-protocol-auth-bypass(52379) Source: SUSE Type: SUSE-SR:2009:020 SUSE Security Summary Report | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |