IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive information, or inject Lotus Script or other character sequences into a session.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2007-10-29 14:46
Updated : 2011-03-07 19:00
NVD link : CVE-2007-5544
Mitre link : CVE-2007-5544
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
ibm
- lotus_domino
- lotus_notes