Show plain JSON{"id": "CVE-2009-4843", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2010-05-07T18:24:15.377", "references": [{"url": "http://secunia.com/advisories/37297", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.securenetwork.it/ricerca/advisory/download/SN-2009-02.txt", "tags": ["Exploit"], "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/archive/1/507729/100/0/threaded", "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/37297", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securenetwork.it/ricerca/advisory/download/SN-2009-02.txt", "tags": ["Exploit"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/507729/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-287"}]}], "descriptions": [{"lang": "en", "value": "ToutVirtual VirtualIQ Pro before 3.5 build 8691 does not require administrative authentication for JBoss console access, which allows remote attackers to execute arbitrary commands via requests to (1) the JMX Management Console or (2) the Web Console."}, {"lang": "es", "value": "ToutVirtual VirtualIQ Pro anteriores a v3.5 build 8691 no requiere autenticaci\u00f3n administrativa para el acceso a la consola JBoss, lo que permite a atacantes remotos ejecutar comandos de su elecci\u00f3n a trav\u00e9s de peticiones sobre (1) JMX Management Console o (2) Web Console."}], "lastModified": "2025-04-11T00:51:21.963", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:toutvirtual:virtualiq:3.5:-:pro:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FAD9D8B2-EA53-47AF-8703-C9B8F2B2B9DC"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}