IBM Lotus Notes Mail Client Remote Code Execution Vulnerability
RISK: Medium Risk
TYPE: Clients - Email Clients
A vulnerability has been identified in IBM Lotus Notes, which can be exploited by remote user to cause Java applets to be executed on the target user's system. The mail client does not filter 'applet' and 'javascript' tags in HTML-based email messages. A remote user can send a specially crafted email message that, when loaded by the target user, will execute arbitrary Java code on the target system. The code will run with the privileges of the target user.
Impact
- Remote Code Execution
System / Technologies affected
- IBM Lotus Notes 8.0.x, 8.5.x, 9.0
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to the fix which is included in Interim Fix 1 for Notes 8.5.3 Fix Pack 4 and Interim Fix 1 for Notes 9.0.
http://www-304.ibm.com/support/docview.wss?uid=swg21633819
Vulnerability Identifier
Source
Related Link
Share with