PT-2010-1824 · Ibm · Ibm Lotus Notes Traveler

Published

2010-12-16

·

Updated

2017-08-17

·

CVE-2009-5033

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Lotus Notes Traveler versions prior to 8.5.0.2
Description The issue arises from improper handling of a "* *" argument sequence for a certain tell command, allowing remote authenticated users to obtain access to other users' data via a sync operation. This is related to the storage of multiple users' data within the same thread.
Recommendations For versions prior to 8.5.0.2, update to version 8.5.0.2 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-5033

Affected Products

Ibm Lotus Notes Traveler