CVE-2009-0668

critical

Description

Unspecified vulnerability in Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to execute arbitrary Python code via vectors involving the ZEO network protocol.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/52377

http://www.vupen.com/english/advisories/2009/2217

http://www.securityfocus.com/bid/35987

http://secunia.com/advisories/36205

http://secunia.com/advisories/36204

http://pypi.python.org/pypi/ZODB3/3.8.2#whats-new-in-zodb-3-8-2

http://osvdb.org/56827

http://mail.zope.org/pipermail/zope-announce/2009-August/002220.html

Details

Source: Mitre, NVD

Published: 2009-08-07

Updated: 2025-04-09

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

CVSS v4

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N

Severity: Critical

EPSS

EPSS: 0.0064