Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2009-5127 | A stack-based buffer overflow exists in the UtilConfigHome.csp endpoint of InterSystems Caché 2009.1. The vulnerability is triggered by sending a specially crafted HTTP GET request containing an oversized argument to the .csp handler. Due to insufficient bounds checking, the input overflows a stack buffer, allowing an attacker to overwrite control structures and execute arbitrary code. It is unknown if this vulnerability was patched and an affected version range remains undefined. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 22 Nov 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Intersystems
Intersystems cache |
|
| CPEs | cpe:2.3:a:intersystems:cache:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Intersystems
Intersystems cache |
Tue, 16 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Sep 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow exists in the UtilConfigHome.csp endpoint of InterSystems Caché 2009.1. The vulnerability is triggered by sending a specially crafted HTTP GET request containing an oversized argument to the .csp handler. Due to insufficient bounds checking, the input overflows a stack buffer, allowing an attacker to overwrite control structures and execute arbitrary code. It is unknown if this vulnerability was patched and an affected version range remains undefined. | |
| Title | InterSystems Caché UtilConfigHome.csp Stack Buffer Overflow | |
| Weaknesses | CWE-121 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-22T12:32:31.038Z
Reserved: 2025-08-27T18:34:34.963Z
Link: CVE-2009-20005
Updated: 2025-09-16T18:18:24.324Z
Status : Awaiting Analysis
Published: 2025-09-16T15:15:41.780
Modified: 2025-09-17T14:18:55.093
Link: CVE-2009-20005
No data.
OpenCVE Enrichment
No data.
EUVD