CVE-2009-4515: Medium severity speedtech storm vulnerability
Published Dec 31, 2009
·Updated
The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote attackers to read node titles via unspecified vectors.
Affected Software
27 affected components
SpeedTech Storm=6.x-1.0
SpeedTech Storm=6.x-1.1
SpeedTech Storm=6.x-1.2
SpeedTech Storm=6.x-1.3
SpeedTech Storm=6.x-1.4
SpeedTech Storm=6.x-1.5
SpeedTech Storm=6.x-1.6
SpeedTech Storm=6.x-1.7
SpeedTech Storm=6.x-1.8
SpeedTech Storm=6.x-1.9
SpeedTech Storm=6.x-1.10
SpeedTech Storm=6.x-1.11
SpeedTech Storm=6.x-1.12
SpeedTech Storm=6.x-1.13
SpeedTech Storm=6.x-1.14
SpeedTech Storm=6.x-1.15
SpeedTech Storm=6.x-1.16
SpeedTech Storm=6.x-1.17
SpeedTech Storm=6.x-1.18
SpeedTech Storm=6.x-1.19
SpeedTech Storm=6.x-1.20
SpeedTech Storm=6.x-1.21
SpeedTech Storm=6.x-1.22
SpeedTech Storm=6.x-1.23
SpeedTech Storm=6.x-1.24
SpeedTech Storm=6.x-1.x-dev
Drupal Drupal
Event History
Dec 31, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
07:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4515?
CVE-2009-4515 has a medium severity level as it allows remote attackers to read sensitive node titles without proper privileges.
2
How do I fix CVE-2009-4515?
To fix CVE-2009-4515, update the Storm module to version 6.x-1.25 or later.
3
What versions of the Storm module are affected by CVE-2009-4515?
CVE-2009-4515 affects all versions of the Storm module prior to 6.x-1.25.
4
What type of vulnerability is CVE-2009-4515?
CVE-2009-4515 is an access control vulnerability that allows unauthorized reading of node titles.
5
Who can be impacted by CVE-2009-4515?
Users with remote access can be impacted by CVE-2009-4515 if the Storm module is running a vulnerable version.