PT-2004-1244 · Ibm · Lotus Notes & Domino
L0Om
·
Publicado
2004-01-08
·
Atualizado
2024-02-14
·
CVE-2004-0029
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Lotus Notes Domino version 6.0.2
Description
The issue concerns a configuration file, specifically the notes.ini file, which is installed with world-writable permissions on Linux systems. This allows local users to modify the Notes configuration, potentially leading to privilege escalation.
Recommendations
For Lotus Notes Domino version 6.0.2, change the permissions of the notes.ini configuration file to prevent world-writable access, restricting modifications to authorized users only.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Lotus Notes & Domino