PT-2016-4136 · Ibm · Ibm Domino
Published
2016-06-29
·
Updated
2019-10-16
·
CVE-2016-0304
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Domino versions 8.5.x through 8.5.3 FP6 IF12 and versions 9.x through 9.0.1 FP5
Description
The Java Console in IBM Domino, when used with a certain unsupported configuration involving UNC share pathnames, allows remote attackers to bypass authentication and possibly execute arbitrary code. This issue exists due to an incomplete fix for a previous security flaw.
Recommendations
For IBM Domino versions 8.5.x through 8.5.3 FP6 IF12, update to version 8.5.3 FP6 IF13 or later.
For IBM Domino versions 9.x through 9.0.1 FP5, update to version 9.0.1 FP6 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Domino