{"api_version":"1","generated_at":"2026-07-24T18:33:59+00:00","cve":"CVE-2009-0215","urls":{"html":"https://cve.report/CVE-2009-0215","api":"https://cve.report/api/cve/CVE-2009-0215.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0215","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0215"},"summary":{"title":"CVE-2009-0215","description":"Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors.","state":"PUBLISHED","assigner":"certcc","published_at":"2009-03-25 15:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/340420","name":"http://www.kb.cert.org/vuls/id/340420","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"VU#340420 - IBM Access Support ActiveX control stack buffer overflow","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/34228","name":"http://www.securityfocus.com/bid/34228","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Access Support ActiveX Control 'GetXMLValue()'  Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/34470","name":"http://secunia.com/advisories/34470","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Access Support ActiveX Control \"GetXMLValue()\" Buffer Overflow - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/0824","name":"http://www.vupen.com/english/advisories/2009/0824","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/52958","name":"http://osvdb.org/52958","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49409","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49409","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0215","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0215","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"215","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"access_support_activex_control","cpe6":"3.20.284.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:24:18.248Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"52958","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/52958"},{"name":"ibm-access-activex-bo(49409)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49409"},{"name":"34470","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34470"},{"name":"ADV-2009-0824","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/0824"},{"name":"34228","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/34228"},{"name":"VU#340420","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/340420"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-03-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"52958","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/52958"},{"name":"ibm-access-activex-bo(49409)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49409"},{"name":"34470","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34470"},{"name":"ADV-2009-0824","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/0824"},{"name":"34228","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/34228"},{"name":"VU#340420","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/340420"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2009-0215","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"52958","refsource":"OSVDB","url":"http://osvdb.org/52958"},{"name":"ibm-access-activex-bo(49409)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49409"},{"name":"34470","refsource":"SECUNIA","url":"http://secunia.com/advisories/34470"},{"name":"ADV-2009-0824","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/0824"},{"name":"34228","refsource":"BID","url":"http://www.securityfocus.com/bid/34228"},{"name":"VU#340420","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/340420"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2009-0215","datePublished":"2009-03-25T15:00:00.000Z","dateReserved":"2009-01-20T00:00:00.000Z","dateUpdated":"2024-08-07T04:24:18.248Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-03-25 15:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:access_support_activex_control:3.20.284.0:*:*:*:*:*:*:*","matchCriteriaId":"9AE3A9DF-C502-4C74-8FD6-A5FC152BB317"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"215","Ordinal":"1","Title":"CVE-2009-0215","CVE":"CVE-2009-0215","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"215","Ordinal":"1","NoteData":"Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors.","Type":"Description","Title":"CVE-2009-0215"},{"CveYear":"2009","CveId":"215","Ordinal":"2","NoteData":"2009-03-25","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"215","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}