{"api_version":"1","generated_at":"2026-07-24T18:23:10+00:00","cve":"CVE-2009-3409","urls":{"html":"https://cve.report/CVE-2009-3409","api":"https://cve.report/api/cve/CVE-2009-3409.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-3409","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-3409"},"summary":{"title":"CVE-2009-3409","description":"Unspecified vulnerability in the PeopleSoft Enterprise HCM (TAM) component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 9.0 Bundle 10 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.","state":"PUBLISHED","assigner":"oracle","published_at":"2009-10-22 18:30:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.6","severity":"","vector":"AV:N/AC:H/Au:S/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:P/A:N","baseScore":3.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/36776","name":"http://www.securityfocus.com/bid/36776","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle PeopleSoft Enterprise Human Capital Management CVE-2009-3409 Remote Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html","name":"http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Critical Patch Update Advisory - October 2009","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1023061","name":"http://www.securitytracker.com/id?1023061","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle PeopleSoft PeopleTools Bugs Let Remote Authenticated Users Access and Modify Data and Cause Denial of Service Conditions - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA09-294A.html","name":"http://www.us-cert.gov/cas/techalerts/TA09-294A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA09-294A -- Oracle Updates for Multiple Vulnerabilities","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-3409","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3409","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"3409","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"jd_edwards_enterpriseone","cpe6":"9.0","cpe7":"bundle10","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3409","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"peoplesoft_enterprise","cpe6":"9.0","cpe7":"bundle10","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:22:24.581Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"TA09-294A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA09-294A.html"},{"name":"1023061","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023061"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html"},{"name":"36776","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36776"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-10-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in the PeopleSoft Enterprise HCM (TAM) component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 9.0 Bundle 10 allows remote authenticated users to affect confidentiality and integrity via unknown vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-10-27T09:00:00.000Z","orgId":"43595867-4340-4103-b7a2-9a5208d29a85","shortName":"oracle"},"references":[{"name":"TA09-294A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA09-294A.html"},{"name":"1023061","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023061"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html"},{"name":"36776","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36776"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert_us@oracle.com","ID":"CVE-2009-3409","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the PeopleSoft Enterprise HCM (TAM) component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 9.0 Bundle 10 allows remote authenticated users to affect confidentiality and integrity via unknown vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"TA09-294A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA09-294A.html"},{"name":"1023061","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1023061"},{"name":"http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html"},{"name":"36776","refsource":"BID","url":"http://www.securityfocus.com/bid/36776"}]}}}},"cveMetadata":{"assignerOrgId":"43595867-4340-4103-b7a2-9a5208d29a85","assignerShortName":"oracle","cveId":"CVE-2009-3409","datePublished":"2009-10-22T18:00:00.000Z","dateReserved":"2009-09-25T00:00:00.000Z","dateUpdated":"2024-08-07T06:22:24.581Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-10-22 18:30:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:P/A:N","baseScore":3.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jd_edwards_enterpriseone:9.0:bundle10:*:*:*:*:*:*","matchCriteriaId":"F04181E3-4D46-475F-B639-8CD206B1F793"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise:9.0:bundle10:*:*:*:*:*:*","matchCriteriaId":"1962EB4D-FA1A-4646-B8F4-8F4982C5FB3E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"3409","Ordinal":"1","Title":"CVE-2009-3409","CVE":"CVE-2009-3409","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"3409","Ordinal":"1","NoteData":"Unspecified vulnerability in the PeopleSoft Enterprise HCM (TAM) component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 9.0 Bundle 10 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.","Type":"Description","Title":"CVE-2009-3409"},{"CveYear":"2009","CveId":"3409","Ordinal":"2","NoteData":"2009-10-22","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"3409","Ordinal":"3","NoteData":"2009-10-27","Type":"Other","Title":"Modified"}]}}}