The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2011-03-25 12:55
Updated : 2018-10-09 12:31
NVD link : CVE-2011-1519
Mitre link : CVE-2011-1519
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
ibm
- lotus_domino