« Volver al listado

CVE-2009-0662

Estado: ModificadaMedia (6)—

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-0662",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-04-23T17:30:01.640",
  "references": [
    {
      "url": "http://osvdb.org/53975",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://plone.org/products/plone/security/advisories/cve-2009-0662",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/34840",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/34664",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50061",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/53975",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://plone.org/products/plone/security/advisories/cve-2009-0662",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/34840",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/34664",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50061",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "El producto PlonePAS 3.x anterior a la version 3.9 y 3.2.x en versiones anteriores a la 3.2.2, un producto para Plone, no maneja adecuadamente el formulario de login, lo que permite a atacantes remotos autenticados adquirir la identidad de un usuario de su elección a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-16T23:05:31.420",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:plone:plonepas:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ACA0C288-C190-41CB-8B86-B5C791D906E0"
            },
            {
              "criteria": "cpe:2.3:a:plone:plonepas:3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E832934C-0738-47D2-A3DA-16040EA41C40"
            },
            {
              "criteria": "cpe:2.3:a:plone:plonepas:3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9535495-6677-49F9-BDE1-F7472899C3C6"
            },
            {
              "criteria": "cpe:2.3:a:plone:plonepas:3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "447AB0B6-4016-4DD4-9151-1D90BE8B70D8"
            },
            {
              "criteria": "cpe:2.3:a:plone:plonepas:3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B7969846-24D4-4AE9-858D-A4292A65AADB"
            },
            {
              "criteria": "cpe:2.3:a:plone:plonepas:3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A230672-0497-45C8-A511-BAD673193C25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:plone:plone:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0E87B987-557F-49BB-A837-34142D9C3761"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}