Skip to main content

IBM Lotus Domino Cookie File Authentication Bypass and Code Execution Vulnerability

Last Update Date: 25 Mar 2011 11:57 Release Date: 25 Mar 2011 6802 Views

RISK: High Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability has been identified in IBM Lotus Domino, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a design error in the remote console functionality that relies on a user-supplied COOKIEFILE path to retrieve stored credentials and then compares them to the user-provided username and cookie, which could be exploited by remote attackers to bypass authentication and execute arbitrary code with SYSTEM privileges.

It is not aware of any vendor-supplied patch.


Impact

  • Remote Code Execution

System / Technologies affected

  • IBM Lotus Domino versions 8.x

Solutions

  • It is not aware of any vendor-supplied patch.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link