PT-2012-3857 · Ibm · Ibm Lotus Notes

Publicado

2012-06-20

·

Atualizado

2017-08-29

·

CVE-2012-2174

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Lotus Notes versions prior to 8.5.3 FP2
Description The issue concerns a URL handler in IBM Lotus Notes that allows remote attackers to execute arbitrary code via a crafted notes:// URL. This is a result of a command injection vulnerability in the URL handling mechanism.
Recommendations For versions prior to 8.5.3 FP2, update to version 8.5.3 FP2 or later to resolve the issue.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-2174
ZDI-12-154

Produtos afetados

Ibm Lotus Notes