CVE-2009-2701: Critical severity zope zodb vulnerability
Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2701?
CVE-2009-2701 has a medium severity level due to the potential for remote authenticated users to read or delete arbitrary files.
How do I fix CVE-2009-2701?
To fix CVE-2009-2701, upgrade Zope Object Database (ZODB) to version 3.8.3 or 3.9.0c2.
What versions are affected by CVE-2009-2701?
CVE-2009-2701 affects ZODB versions 3.8.0 to 3.8.2 and 3.9.0b1 to 3.9.0b5.
Who is impacted by CVE-2009-2701?
Remote authenticated users of affected ZODB versions are impacted by CVE-2009-2701.
What functionality is exploited in CVE-2009-2701?
CVE-2009-2701 exploits the ZEO storage-server functionality when specific database sharing and blob support is enabled.