CVE-2009-4844 describes an information disclosure vulnerability in ToutVirtual VirtualIQ Pro 3.2 build 7882. The software fails to restrict access to the /status URI on port 9080, allowing remote attackers to directly request and obtain sensitive Tomcat information. With a CVSS score of 5.0, this low-complexity network-based attack could lead to unauthorized information disclosure (C:P), but not impact integrity or availability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this decade-old vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2_build_7882CPE matchmatch criteria | cpe:2.3:a:toutvirtual:virtualiq:3.2_build_7882:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.