CVE-2009-0669

EUVD-2009-0013
Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass authentication via vectors involving the ZEO network protocol.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
Affected Products (NVD)
VendorProductVersion
zopezodb
𝑥
≤ 3.8.1
zopezodb
3.8
zopezodb
3.8.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
zodb
dapper
ignored
hardy
ignored
intrepid
ignored
jaunty
ignored
karmic
not-affected
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
zope2.10
dapper
dne
hardy
ignored
intrepid
Fixed 2.10.6-1+lenny1build0.8.10.1
released
jaunty
Fixed 2.10.6-1+lenny1build0.9.04.1
released
karmic
not-affected
lucid
dne
maverick
dne
natty
dne
oneiric
dne
zope2.11
dapper
dne
hardy
dne
intrepid
dne
jaunty
dne
karmic
ignored
lucid
dne
maverick
dne
natty
dne
oneiric
dne
zope2.8
dapper
ignored
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
zope2.9
dapper
ignored
hardy
ignored
intrepid
ignored
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
zope3
dapper
Fixed 3.2.1-1ubuntu1.2
released
hardy
Fixed 3.3.1-5ubuntu2.2
released
intrepid
Fixed 3.3.1-7ubuntu0.2
released
jaunty
Fixed 3.4.0-0ubuntu3.3
released
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne