CVE-2009-1055
Last modified
CVE-2009-1055 is a vulnerability of currently unknown severity. Unspecified vulnerability in the web service in Sitecore CMS 5.3.1 rev. 071114 allows remote authenticated users to gain access to security databases, and obtain administrative and user credentials, via unknown vectors related to SOAP and XML requests.. EPSS estimates a 1.15% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in the web service in Sitecore CMS 5.3.1 rev. 071114 allows remote authenticated users to gain access to security databases, and obtain administrative and user credentials, via unknown vectors related to SOAP and XML requests.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sitecore | Cms | 5.3.0 |
| Sitecore | Cms | 5.3.1 |
References
- http://secunia.com/advisories/34356Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0753Vendor Advisory
- http://secunia.com/advisories/34356Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0753Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-1055?
How severe is CVE-2009-1055?
How do I fix CVE-2009-1055?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-1049SQL injection vulnerability in articleCall.php in Bloginator…
- CVE-2009-1050Bloginator 1A allows remote attackers to bypass authenticati…
- CVE-2009-1051FubarForum 1.6 and earlier stores sensitive information unde…
- CVE-2009-1052FireAnt 1.3 and earlier stores sensitive information under t…
- CVE-2009-1053chaozzDB 1.2 and earlier stores sensitive information under …
- CVE-2009-1054Unspecified vulnerability in JustSystems Ichitaro 13, 2004 t…
- CVE-2009-1056IBM Rational AppScan Enterprise before 5.5 FP1 allows remote…
- CVE-2009-1057MicroSmarts Enterprise ZipItFast! 3.0 allows remote attacker…
- CVE-2009-1058Stack-based buffer overflow in ZipGenius might allow remote …
- CVE-2009-1059Stack-based buffer overflow in Trident PowerZip 7.2 might al…
- CVE-2009-1060Unspecified vulnerability in Apple Safari on Mac OS X 10.5.6…
- CVE-2009-1061Unspecified vulnerability in Adobe Acrobat Reader 9 before 9…
Are you affected by CVE-2009-1055?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
