PT-2001-2167 · Ibm · Lotus Domino Server
Published
2001-09-20
·
Updated
2017-12-19
·
CVE-2001-1018
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Lotus Domino web server version 5.08
Description
The issue allows remote attackers to determine the internal IP address of the server when NAT is enabled. This is achieved by sending a GET request that contains a long sequence of / (slash) characters.
Recommendations
For version 5.08, consider restricting access to the web server or implementing additional security measures to prevent unauthorized requests until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lotus Domino Server