{"api_version":"1","generated_at":"2026-07-23T08:37:44+00:00","cve":"CVE-2009-0064","urls":{"html":"https://cve.report/CVE-2009-0064","api":"https://cve.report/api/cve/CVE-2009-0064.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0064","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0064"},"summary":{"title":"CVE-2009-0064","description":"Multiple unspecified vulnerabilities in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allow remote authenticated users to gain privileges, and possibly obtain sensitive information or hijack sessions of arbitrary users, via vectors involving (1) administrative scripts or (2) console functions.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-04-24 15:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9","severity":"","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://osvdb.org/53945","name":"http://osvdb.org/53945","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://securitytracker.com/id?1022117","name":"http://securitytracker.com/id?1022117","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Symantec Brightmail Appliance Brightmail Control Center Lets Remote Authenticated Users Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/1155","name":"http://www.vupen.com/english/advisories/2009/1155","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50075","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50075","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/34885","name":"http://secunia.com/advisories/34885","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Brightmail Gateway Control Center Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090423_01","name":"http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090423_01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Broadcom Support Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/34639","name":"http://www.securityfocus.com/bid/34639","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Brightmail Gateway Control Center Remote Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0064","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0064","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"64","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"symantec","cpe5":"brightmail_gateway_appliance","cpe6":"7.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"64","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"symantec","cpe5":"brightmail_gateway_appliance","cpe6":"7.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"64","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"symantec","cpe5":"brightmail_gateway_appliance","cpe6":"7.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"64","vulnerable":"1","versionEndIncluding":"8.0","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"symantec","cpe5":"brightmail_gateway_appliance","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:24:17.008Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"brightmail-consolescripts-priv-escalation(50075)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50075"},{"name":"1022117","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1022117"},{"name":"ADV-2009-1155","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/1155"},{"name":"53945","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/53945"},{"name":"34885","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34885"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090423_01"},{"name":"34639","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/34639"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-04-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple unspecified vulnerabilities in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allow remote authenticated users to gain privileges, and possibly obtain sensitive information or hijack sessions of arbitrary users, via vectors involving (1) administrative scripts or (2) console functions."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"brightmail-consolescripts-priv-escalation(50075)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50075"},{"name":"1022117","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1022117"},{"name":"ADV-2009-1155","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/1155"},{"name":"53945","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/53945"},{"name":"34885","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34885"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090423_01"},{"name":"34639","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/34639"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-0064","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple unspecified vulnerabilities in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allow remote authenticated users to gain privileges, and possibly obtain sensitive information or hijack sessions of arbitrary users, via vectors involving (1) administrative scripts or (2) console functions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"brightmail-consolescripts-priv-escalation(50075)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/50075"},{"name":"1022117","refsource":"SECTRACK","url":"http://securitytracker.com/id?1022117"},{"name":"ADV-2009-1155","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/1155"},{"name":"53945","refsource":"OSVDB","url":"http://osvdb.org/53945"},{"name":"34885","refsource":"SECUNIA","url":"http://secunia.com/advisories/34885"},{"name":"http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090423_01","refsource":"CONFIRM","url":"http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090423_01"},{"name":"34639","refsource":"BID","url":"http://www.securityfocus.com/bid/34639"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-0064","datePublished":"2009-04-24T15:00:00.000Z","dateReserved":"2009-01-07T00:00:00.000Z","dateUpdated":"2024-08-07T04:24:17.008Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-04-24 15:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:symantec:brightmail_gateway_appliance:*:*:*:*:*:*:*:*","versionEndIncluding":"8.0","matchCriteriaId":"142AC359-363A-4B84-8154-2E6D178E33EB"},{"vulnerable":true,"criteria":"cpe:2.3:h:symantec:brightmail_gateway_appliance:7.5:*:*:*:*:*:*:*","matchCriteriaId":"DC321D15-6374-4D17-A7A7-05257692AA87"},{"vulnerable":true,"criteria":"cpe:2.3:h:symantec:brightmail_gateway_appliance:7.6:*:*:*:*:*:*:*","matchCriteriaId":"F74170B9-18E6-4275-BD5C-7223EAA08AD0"},{"vulnerable":true,"criteria":"cpe:2.3:h:symantec:brightmail_gateway_appliance:7.7:*:*:*:*:*:*:*","matchCriteriaId":"DDCFFB37-7043-47BB-9906-6D1EFA7B8FC0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"64","Ordinal":"1","Title":"CVE-2009-0064","CVE":"CVE-2009-0064","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"64","Ordinal":"1","NoteData":"Multiple unspecified vulnerabilities in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allow remote authenticated users to gain privileges, and possibly obtain sensitive information or hijack sessions of arbitrary users, via vectors involving (1) administrative scripts or (2) console functions.","Type":"Description","Title":"CVE-2009-0064"},{"CveYear":"2009","CveId":"64","Ordinal":"2","NoteData":"2009-04-24","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"64","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}