CVE-2011-3587

critical
Published 2011-10-10 · Modified 2024-12-03
CVSS v3
CVSS v2
9.3
VIR risk
9.3

Description

Zope Command Execution Vulnerability

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=742297

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://zope2.zope.org/news/security-vulnerability-announcement-cve-2011-3587

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/46221

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://plone.org/products/plone/security/advisories/20110928

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://plone.org/products/plone-hotfix/releases/20110928

Package impact

EcosystemPackageVulnerableFixed
python PyPIzope2>=2.12.0,<2.12.202.12.20
python PyPIzope2>=2.13.0,<2.13.102.13.10

Application impact

VendorProductVersionsFixed
ploneplone4.0
ploneplone4.0.1
ploneplone4.0.2
ploneplone4.0.3
ploneplone4.0.4
ploneplone4.0.5
ploneplone4.0.6.1
ploneplone4.0.7
ploneplone4.0.8
ploneplone4.0.9
ploneplone4.1
ploneplone4.2
ploneplone4.2a1
ploneplone4.2a2
zopezope2.12.0
zopezope2.12.1
zopezope2.12.2
zopezope2.12.3
zopezope2.12.4
zopezope2.12.5
zopezope2.12.6
zopezope2.12.7
zopezope2.12.8
zopezope2.12.9
zopezope2.12.10
zopezope2.12.11
zopezope2.12.12
zopezope2.12.13
zopezope2.12.14
zopezope2.12.15
zopezope2.12.16
zopezope2.12.17
zopezope2.12.18
zopezope2.12.19
zopezope2.12.20
zopezope2.13.0
zopezope2.13.1
zopezope2.13.2
zopezope2.13.3
zopezope2.13.4
zopezope2.13.5
zopezope2.13.6
zopezope2.13.7
zopezope2.13.8
zopezope2.13.9
zopezope2.13.10

References

Verify integrity in audit chain (admin only). AS-IS.