Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2009-0011 | Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors. | 
  Github GHSA | 
                GHSA-m52m-2qpx-9j4j | Zope Object Database (ZODB) Arbitrary files reading and deletion | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Wed, 28 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
Thu, 22 May 2025 04:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T20:36:27.354Z
Reserved: 2009-08-05T00:00:00Z
Link: CVE-2009-2701
No data.
Status : Deferred
Published: 2009-09-08T18:30:00.233
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-2701
                        OpenCVE Enrichment
                    No data.
 EUVD
 Github GHSA