PT-2006-4638 · Ibm · Ibm Lotus Notes
Publicado
2006-07-21
·
Atualizado
2008-09-05
·
CVE-2006-3778
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Lotus Notes versions 6.0 through 7.0
Description
The issue arises from improper handling of replies to e-mail messages with alternate name users. This occurs under two specific conditions: when the "Save As Draft" option is used or when a comma is present inside the phrase portion of an address. As a result, e-mails can be sent to users who were previously deleted from the To, CC, and BCC fields, potentially allowing remote attackers to obtain the list of original recipients.
Recommendations
For versions 6.0 through 7.0, consider disabling the "Save As Draft" option and avoid using commas within the phrase portion of addresses until a proper fix is applied. Restrict access to sensitive e-mail features to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ibm Lotus Notes