{"api_version":"1","generated_at":"2026-07-23T12:32:17+00:00","cve":"CVE-2009-2681","urls":{"html":"https://cve.report/CVE-2009-2681","api":"https://cve.report/api/cve/CVE-2009-2681.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-2681","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-2681"},"summary":{"title":"CVE-2009-2681","description":"Unspecified vulnerability in HP ProCurve Identity Driven Manager (IDM) A.02.x through A.02.03 and A.03.x through A.03.00, on Windows Server 2003 with IAS and Windows Server 2008 with NPS, allows local users to gain privileges via unknown vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-09-29 18:00:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:L/AC:L/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:C/I:C/A:C","baseScore":6.8,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://securitytracker.com/id?1022915","name":"http://securitytracker.com/id?1022915","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"HP ProCurve Identity Driven Manager Lets Local Users Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.vupen.com/english/advisories/2009/2707","name":"http://www.vupen.com/english/advisories/2009/2707","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36792","name":"http://secunia.com/advisories/36792","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"HP ProCurve Identity Driven Manager Privilege Escalation Vulnerability - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01798159","name":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01798159","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/36462","name":"http://www.securityfocus.com/bid/36462","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"HP ProCurve Identity Driven Manager (IDM) Unspecified Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-2681","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-2681","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"2681","vulnerable":"1","versionEndIncluding":"a.02.03","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"procurve_identity_driven_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2681","vulnerable":"1","versionEndIncluding":"a.03.00","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"procurve_identity_driven_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2681","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2003","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2681","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2008","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:59:56.389Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"SSRT090082","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01798159"},{"name":"36792","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36792"},{"name":"36462","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36462"},{"name":"ADV-2009-2707","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/2707"},{"name":"HPSBGN02441","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01798159"},{"name":"1022915","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1022915"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Unspecified vulnerability in HP ProCurve Identity Driven Manager (IDM) A.02.x through A.02.03 and A.03.x through A.03.00, on Windows Server 2003 with IAS and Windows Server 2008 with NPS, allows local users to gain privileges via unknown vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-09-29T17:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"SSRT090082","tags":["vendor-advisory","x_refsource_HP"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01798159"},{"name":"36792","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36792"},{"name":"36462","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36462"},{"name":"ADV-2009-2707","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/2707"},{"name":"HPSBGN02441","tags":["vendor-advisory","x_refsource_HP"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01798159"},{"name":"1022915","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1022915"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-2681","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in HP ProCurve Identity Driven Manager (IDM) A.02.x through A.02.03 and A.03.x through A.03.00, on Windows Server 2003 with IAS and Windows Server 2008 with NPS, allows local users to gain privileges via unknown vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"SSRT090082","refsource":"HP","url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01798159"},{"name":"36792","refsource":"SECUNIA","url":"http://secunia.com/advisories/36792"},{"name":"36462","refsource":"BID","url":"http://www.securityfocus.com/bid/36462"},{"name":"ADV-2009-2707","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/2707"},{"name":"HPSBGN02441","refsource":"HP","url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01798159"},{"name":"1022915","refsource":"SECTRACK","url":"http://securitytracker.com/id?1022915"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-2681","datePublished":"2009-09-29T17:00:00.000Z","dateReserved":"2009-08-05T00:00:00.000Z","dateUpdated":"2024-09-17T03:43:28.729Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-09-29 18:00:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:C/I:C/A:C","baseScore":6.8,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.1,"impactScore":10,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hp:procurve_identity_driven_manager:*:*:*:*:*:*:*:*","versionEndIncluding":"a.02.03","matchCriteriaId":"DE902038-73BC-4C6F-8181-71A7EC6B82EB"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:procurve_identity_driven_manager:*:*:*:*:*:*:*:*","versionEndIncluding":"a.03.00","matchCriteriaId":"F13F4001-1A2C-433C-AE46-FE6EA1A87984"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:*:*","matchCriteriaId":"31A64C69-D182-4BEC-BA8A-7B405F5B2FC0"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2008:*:*:*:*:*:*:*:*","matchCriteriaId":"6B33C9BD-FC34-4DFC-A81F-C620D3DAA79D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"2681","Ordinal":"1","Title":"CVE-2009-2681","CVE":"CVE-2009-2681","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"2681","Ordinal":"1","NoteData":"Unspecified vulnerability in HP ProCurve Identity Driven Manager (IDM) A.02.x through A.02.03 and A.03.x through A.03.00, on Windows Server 2003 with IAS and Windows Server 2008 with NPS, allows local users to gain privileges via unknown vectors.","Type":"Description","Title":"CVE-2009-2681"},{"CveYear":"2009","CveId":"2681","Ordinal":"2","NoteData":"2009-09-29","Type":"Other","Title":"Published"}]}}}