PT-2008-2480 · Ibm · Ibm Lotus Notes
Published
2008-02-21
·
Updated
2011-03-08
·
CVE-2008-0862
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Lotus Notes versions 6.0 through 8.0
Description
The issue allows remote attackers to bypass Execution Control List (ECL) protection by signing an unsigned applet when a user forwards an email message. This occurs due to a flaw in how IBM Lotus Notes handles unsigned applets in forwarded email messages.
Recommendations
For versions 6.0 through 8.0, consider disabling the feature that signs unsigned applets when forwarding email messages as a temporary workaround until a patch is available. Restrict access to unsigned applets to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Lotus Notes