CVE-2017-1000009

critical
Published 2017-07-17 · Modified 2024-04-25
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
VIR risk
9.8

Description

Akeneo PIM vulnerable to shell injection in the mass edition

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Package impact

EcosystemPackageVulnerableFixed
php Packagistakeneo/pim-community-dev>=1.4,<1.4.281.4.28
php Packagistakeneo/pim-community-dev>=1.5,<1.5.151.5.15
php Packagistakeneo/pim-community-dev>=1.6,<1.6.61.6.6

Application impact

VendorProductVersionsFixed
akeneoproduct_information_management1.4.0
akeneoproduct_information_management1.4.1
akeneoproduct_information_management1.4.2
akeneoproduct_information_management1.4.3
akeneoproduct_information_management1.4.4
akeneoproduct_information_management1.4.5
akeneoproduct_information_management1.4.6
akeneoproduct_information_management1.4.7
akeneoproduct_information_management1.4.8
akeneoproduct_information_management1.4.9
akeneoproduct_information_management1.4.10
akeneoproduct_information_management1.4.11
akeneoproduct_information_management1.4.12
akeneoproduct_information_management1.4.13
akeneoproduct_information_management1.4.14
akeneoproduct_information_management1.4.15
akeneoproduct_information_management1.4.16
akeneoproduct_information_management1.4.17
akeneoproduct_information_management1.4.18
akeneoproduct_information_management1.4.19
akeneoproduct_information_management1.4.20
akeneoproduct_information_management1.4.21
akeneoproduct_information_management1.4.22
akeneoproduct_information_management1.4.23
akeneoproduct_information_management1.4.24
akeneoproduct_information_management1.4.25
akeneoproduct_information_management1.4.26
akeneoproduct_information_management1.4.27
akeneoproduct_information_management1.5.0
akeneoproduct_information_management1.5.1
akeneoproduct_information_management1.5.2
akeneoproduct_information_management1.5.3
akeneoproduct_information_management1.5.4
akeneoproduct_information_management1.5.5
akeneoproduct_information_management1.5.6
akeneoproduct_information_management1.5.7
akeneoproduct_information_management1.5.8
akeneoproduct_information_management1.5.9
akeneoproduct_information_management1.5.10
akeneoproduct_information_management1.5.11
akeneoproduct_information_management1.5.12
akeneoproduct_information_management1.5.13
akeneoproduct_information_management1.5.14
akeneoproduct_information_management1.6.0
akeneoproduct_information_management1.6.1
akeneoproduct_information_management1.6.2
akeneoproduct_information_management1.6.3
akeneoproduct_information_management1.6.4
akeneoproduct_information_management1.6.5

References

CWEs

CWE-78

💬 Discuss CVE-2017-1000009 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.