[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Authentication bypass vulnerability in COOKIEFILE field in Server Controller in IBM Lotus Domino 7.x and 8.x

ID: oval:org.secpod.oval:def:599Date: (C)2011-04-01   (M)2022-10-10
Class: VULNERABILITYFamily: windows




The host is installed with IBM Lotus Domino and is prone to authentication bypass vulnerability. A flaw is present in the Server Controller authentication mechanism, which accepts UNC share pathnames in the COOKIEFILE field which retrieves stored credentials. Successful exploitation could allow remote attackers to bypass authentication.

Platform:
Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product:
IBM Lotus Domino
Reference:
CVE-2011-1519
CVE    1
CVE-2011-1519
CPE    26
cpe:/a:ibm:lotus_domino:7.0
cpe:/a:ibm:lotus_domino:8.0
cpe:/a:ibm:lotus_domino:8.5.1
cpe:/a:ibm:lotus_domino:8.5.0
...

© SecPod Technologies