PT-2011-3185 · Ibm · Ibm Lotus Domino

Publicado

2011-03-25

·

Atualizado

2018-10-09

·

CVE-2011-1519

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Lotus Domino versions 7.x through 8.x
Description The issue allows remote attackers to bypass authentication and execute arbitrary code by manipulating the COOKIEFILE field to point to a file located at a UNC share pathname. This enables attackers to access the system without proper credentials.
Recommendations For IBM Lotus Domino versions 7.x through 8.x, consider restricting access to the COOKIEFILE field to prevent unauthorized modifications, and ensure that all UNC share pathnames are properly validated to minimize the risk of exploitation.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1519

Produtos afetados

Ibm Lotus Domino