VulnerabilityModified
CVE-2009-1055
Unspecified vulnerability in the web service in Sitecore CMS 5.3.1 rev.
MEDIUM 4.0EPSS 1.15%
Does this matter?
Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the web service in Sitecore CMS 5.3.1 rev. 071114 allows remote authenticated users to gain access to security databases, and obtain administrative and user credentials, via unknown vectors related to SOAP and XML requests.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.15% probability · 65th percentile
- CISA KEV
- Not listed
- Affected
- sitecore/cms
- Source
- cve@mitre.org
References
- http://sdn5.sitecore.net/Products/Sitecore%20V5/Sitecore%20CMS%205%2C-d-%2C3/ReleaseNotes/V5%2C-d-%2C3%2C-d-%2C2/ChangeLog.aspx
- http://secunia.com/advisories/34356Vendor Advisory
- http://www.securityfocus.com/archive/1/501929/100/0/threaded
- http://www.securityfocus.com/bid/34162
- http://www.vupen.com/english/advisories/2009/0753Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49298
- http://sdn5.sitecore.net/Products/Sitecore%20V5/Sitecore%20CMS%205%2C-d-%2C3/ReleaseNotes/V5%2C-d-%2C3%2C-d-%2C2/ChangeLog.aspx
- http://secunia.com/advisories/34356Vendor Advisory
- http://www.securityfocus.com/archive/1/501929/100/0/threaded
- http://www.securityfocus.com/bid/34162
- http://www.vupen.com/english/advisories/2009/0753Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49298
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.