CVE-2009-4498: OS Command Injection
Published Dec 31, 2009
·Updated
The nodeprocesscommand function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request.
Affected Software
14 affected components
Zabbix Zabbix<=1.7.4
Zabbix Zabbix=1.1.2
Zabbix Zabbix=1.1.3
Zabbix Zabbix=1.1.4
Zabbix Zabbix=1.1.5
Zabbix Zabbix=1.4.2
Zabbix Zabbix=1.4.3
Zabbix Zabbix=1.6.6
Zabbix Zabbix=1.6.7
Zabbix Zabbix=1.6.8
Zabbix Zabbix=1.7
Zabbix Zabbix=1.7.1
Zabbix Zabbix=1.7.2
Zabbix Zabbix=1.7.3
Event History
Dec 31, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4498?
CVE-2009-4498 is considered critical as it allows remote attackers to execute arbitrary commands on Zabbix Server.
2
How do I fix CVE-2009-4498?
To fix CVE-2009-4498, upgrade Zabbix Server to version 1.8 or later.
3
Which versions of Zabbix are affected by CVE-2009-4498?
CVE-2009-4498 affects Zabbix Server versions prior to 1.8, including versions from 1.1.2 to 1.7.4.
4
What impact does CVE-2009-4498 have on Zabbix Server?
CVE-2009-4498 can lead to unauthorized command execution, compromising the integrity and security of the server.
5
Is there a workaround for CVE-2009-4498 if I cannot upgrade?
There are no recommended workarounds for CVE-2009-4498, and upgrading is the best solution.