PT-2007-6688 · Ibm · Ibm Lotus Domino
Published
2007-10-29
·
Updated
2017-07-29
·
CVE-2007-5701
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Lotus Domino versions prior to 7.0.3
Description
The issue allows local users or attackers with physical access to obtain sensitive information, such as passwords, when an administrator enters a command with any uppercase character. This results in cleartext password disclosure in the console log and Admin panel due to an incomplete blacklist vulnerability in the Certificate Authority (CA).
Recommendations
For versions prior to 7.0.3, update to version 7.0.3 or later to resolve the issue. As a temporary workaround, consider avoiding the use of uppercase characters when entering "ca activate" or "ca unlock" commands to minimize the risk of password disclosure. Restrict physical access to the system and limit local user privileges to reduce the potential for exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Lotus Domino