PT-2005-3581 · Ibm · Ibm Lotus Notes
Shalom Carmel
·
Published
2005-08-25
·
Updated
2016-10-18
·
CVE-2005-2696
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Lotus Notes (affected versions not specified)
Description
The issue allows remote attackers to obtain sensitive information, specifically password hashes, due to improper access restrictions in the Notes Address Book (NAB). This can be achieved through various means, including accessing the password digest field in the Administration tab of a Lotus Notes client, the
PasswordDigest and HTTPPassword fields in the document properties in the NAB, or by directly querying the Domino LDAP server.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Lotus Notes