{"api_version":"1","generated_at":"2026-07-24T18:44:59+00:00","cve":"CVE-2009-3923","urls":{"html":"https://cve.report/CVE-2009-3923","api":"https://cve.report/api/cve/CVE-2009-3923.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-3923","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-3923"},"summary":{"title":"CVE-2009-3923","description":"The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-11-10 00:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-287","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-268328-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-268328-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#268328: A Security Vulnerability in Sun Virtual Desktop Infrastructure (VDI) Software 3.0 may Lead to Unauthorized Access to the VirtualBox Web Service","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/36917","name":"http://www.securityfocus.com/bid/36917","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Sun Virtual Desktop Infrastructure Authentication Mechanism Unauthorized Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-141481-03-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-141481-03-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54136","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54136","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-3923","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3923","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"3923","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"virtualbox","cpe6":"2.0.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3923","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"virtualbox","cpe6":"2.0.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3923","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"virtual_desktop_infrastructure","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:45:50.449Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"vdi-authentication-unauth-access(54136)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54136"},{"name":"268328","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-268328-1"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-141481-03-1"},{"name":"36917","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36917"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-11-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"vdi-authentication-unauth-access(54136)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54136"},{"name":"268328","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-268328-1"},{"tags":["x_refsource_CONFIRM"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-141481-03-1"},{"name":"36917","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36917"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-3923","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"vdi-authentication-unauth-access(54136)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54136"},{"name":"268328","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-268328-1"},{"name":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-141481-03-1","refsource":"CONFIRM","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-21-141481-03-1"},{"name":"36917","refsource":"BID","url":"http://www.securityfocus.com/bid/36917"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-3923","datePublished":"2009-11-10T00:00:00.000Z","dateReserved":"2009-11-09T00:00:00.000Z","dateUpdated":"2024-08-07T06:45:50.449Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-11-10 00:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-287","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sun:virtual_desktop_infrastructure:3.0:*:*:*:*:*:*:*","matchCriteriaId":"13508CBB-9253-40A6-9CC9-5CD5535A35DD"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:virtualbox:2.0.8:*:*:*:*:*:*:*","matchCriteriaId":"6456F012-E72B-4622-BFD1-F95FEDA6E446"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:virtualbox:2.0.10:*:*:*:*:*:*:*","matchCriteriaId":"0003E19C-EBAA-488F-B3F0-E2CFB283FBDD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"3923","Ordinal":"1","Title":"CVE-2009-3923","CVE":"CVE-2009-3923","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"3923","Ordinal":"1","NoteData":"The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.","Type":"Description","Title":"CVE-2009-3923"},{"CveYear":"2009","CveId":"3923","Ordinal":"2","NoteData":"2009-11-09","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"3923","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}