{"api_version":"1","generated_at":"2026-07-23T23:39:54+00:00","cve":"CVE-2009-2701","urls":{"html":"https://cve.report/CVE-2009-2701","api":"https://cve.report/api/cve/CVE-2009-2701.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-2701","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-2701"},"summary":{"title":"CVE-2009-2701","description":"Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-09-08 18:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6","severity":"","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","baseScore":6,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://mail.zope.org/pipermail/zope-announce/2009-September/002221.html","name":"https://mail.zope.org/pipermail/zope-announce/2009-September/002221.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"[Zope-Annce] CVE-2009-2701: Releases to fix ZODB ZEO server\tvulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://pypi.python.org/pypi/ZODB3/3.9.0c2","name":"http://pypi.python.org/pypi/ZODB3/3.9.0c2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Python Package Index : ZODB3 3.9.0c2","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://pypi.python.org/pypi/ZODB3/3.8.3","name":"http://pypi.python.org/pypi/ZODB3/3.8.3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Python Package Index : ZODB3 3.8.3","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/2534","name":"http://www.vupen.com/english/advisories/2009/2534","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-2701","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-2701","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"2701","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zope","cpe5":"zodb","cpe6":"3.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2701","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zope","cpe5":"zodb","cpe6":"3.8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2701","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zope","cpe5":"zodb","cpe6":"3.8.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2701","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zope","cpe5":"zodb","cpe6":"3.8.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2701","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zope","cpe5":"zodb","cpe6":"3.9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2701","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zope","cpe5":"zodb","cpe6":"3.9.0b1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2701","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zope","cpe5":"zodb","cpe6":"3.9.0b2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2701","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zope","cpe5":"zodb","cpe6":"3.9.0b3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2701","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zope","cpe5":"zodb","cpe6":"3.9.0b4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2701","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zope","cpe5":"zodb","cpe6":"3.9.0b5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2701","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zope","cpe5":"zodb","cpe6":"3.9.0c1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:59:56.947Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"[zope-announce] 20090901 CVE-2009-2701: Releases to fix ZODB ZEO server vulnerability","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://mail.zope.org/pipermail/zope-announce/2009-September/002221.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://pypi.python.org/pypi/ZODB3/3.8.3"},{"name":"ADV-2009-2534","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/2534"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://pypi.python.org/pypi/ZODB3/3.9.0c2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-09-08T18:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"[zope-announce] 20090901 CVE-2009-2701: Releases to fix ZODB ZEO server vulnerability","tags":["mailing-list","x_refsource_MLIST"],"url":"https://mail.zope.org/pipermail/zope-announce/2009-September/002221.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://pypi.python.org/pypi/ZODB3/3.8.3"},{"name":"ADV-2009-2534","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/2534"},{"tags":["x_refsource_CONFIRM"],"url":"http://pypi.python.org/pypi/ZODB3/3.9.0c2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-2701","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"[zope-announce] 20090901 CVE-2009-2701: Releases to fix ZODB ZEO server vulnerability","refsource":"MLIST","url":"https://mail.zope.org/pipermail/zope-announce/2009-September/002221.html"},{"name":"http://pypi.python.org/pypi/ZODB3/3.8.3","refsource":"CONFIRM","url":"http://pypi.python.org/pypi/ZODB3/3.8.3"},{"name":"ADV-2009-2534","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/2534"},{"name":"http://pypi.python.org/pypi/ZODB3/3.9.0c2","refsource":"CONFIRM","url":"http://pypi.python.org/pypi/ZODB3/3.9.0c2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-2701","datePublished":"2009-09-08T18:00:00.000Z","dateReserved":"2009-08-05T00:00:00.000Z","dateUpdated":"2024-09-16T20:36:27.354Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-09-08 18:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","baseScore":6,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:zope:zodb:3.8:*:*:*:*:*:*:*","matchCriteriaId":"FF49B253-411F-4E83-93B3-556783B73965"},{"vulnerable":true,"criteria":"cpe:2.3:a:zope:zodb:3.8.0:*:*:*:*:*:*:*","matchCriteriaId":"8568BD1E-839A-4C78-840D-47807D207C6F"},{"vulnerable":true,"criteria":"cpe:2.3:a:zope:zodb:3.8.1:*:*:*:*:*:*:*","matchCriteriaId":"552E429F-964F-4BF8-B974-C4C59EA7871F"},{"vulnerable":true,"criteria":"cpe:2.3:a:zope:zodb:3.8.2:*:*:*:*:*:*:*","matchCriteriaId":"204FA56B-576D-4274-B17C-6AC4FC1EB58B"},{"vulnerable":true,"criteria":"cpe:2.3:a:zope:zodb:3.9.0:*:*:*:*:*:*:*","matchCriteriaId":"8C5CCCAA-83AD-4CD6-B7FD-46809B786395"},{"vulnerable":true,"criteria":"cpe:2.3:a:zope:zodb:3.9.0b1:*:*:*:*:*:*:*","matchCriteriaId":"2F38F2B2-E061-4D77-9A88-1C432F31FAFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:zope:zodb:3.9.0b2:*:*:*:*:*:*:*","matchCriteriaId":"EFA88DF5-7A25-4187-8B9D-567B0279FEAD"},{"vulnerable":true,"criteria":"cpe:2.3:a:zope:zodb:3.9.0b3:*:*:*:*:*:*:*","matchCriteriaId":"DCFE0BF9-0AC2-4461-BAAE-BDE91A830788"},{"vulnerable":true,"criteria":"cpe:2.3:a:zope:zodb:3.9.0b4:*:*:*:*:*:*:*","matchCriteriaId":"EF8EA11C-98BD-419F-9817-4071B287F87B"},{"vulnerable":true,"criteria":"cpe:2.3:a:zope:zodb:3.9.0b5:*:*:*:*:*:*:*","matchCriteriaId":"283DC1FE-6F98-4FFA-A17F-6277AB9815C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:zope:zodb:3.9.0c1:*:*:*:*:*:*:*","matchCriteriaId":"7A991E3D-03E9-4B2F-90FB-0B308D142B20"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"2701","Ordinal":"1","Title":"CVE-2009-2701","CVE":"CVE-2009-2701","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"2701","Ordinal":"1","NoteData":"Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors.","Type":"Description","Title":"CVE-2009-2701"},{"CveYear":"2009","CveId":"2701","Ordinal":"2","NoteData":"2009-09-08","Type":"Other","Title":"Published"}]}}}