CVE-2011-1519

Current Description

The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.

Basic Data

PublishedMarch 25, 2011
Last ModifiedOctober 09, 2018
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeCWE-287
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:N/AC:L/Au:N/C:C/I:C/A:C
CVSS 2 - Access VectorNETWORK
CVSS 2 - Access ComplexityLOW
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactCOMPLETE
CVSS 2 - Availability ImpactCOMPLETE
CVSS 2 - Base Score10.0
SeverityHIGH
Exploitability Score10.0
Impact Score10.0
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationIbmLotus Domino7.0*******
    2.3ApplicationIbmLotus Domino7.0.1*******
    2.3ApplicationIbmLotus Domino7.0.1.1*******
    2.3ApplicationIbmLotus Domino7.0.2*******
    2.3ApplicationIbmLotus Domino7.0.2.1*******
    2.3ApplicationIbmLotus Domino7.0.2.2*******
    2.3ApplicationIbmLotus Domino7.0.2.3*******
    2.3ApplicationIbmLotus Domino7.0.3*******
    2.3ApplicationIbmLotus Domino7.0.3.1*******
    2.3ApplicationIbmLotus Domino7.0.4*******
    2.3ApplicationIbmLotus Domino7.0.4.1*******
    2.3ApplicationIbmLotus Domino7.0.4.2*******
  • OR - Configuration 2
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationIbmLotus Domino8.0*******
    2.3ApplicationIbmLotus Domino8.0.1*******
    2.3ApplicationIbmLotus Domino8.0.2*******
    2.3ApplicationIbmLotus Domino8.0.2.1*******
    2.3ApplicationIbmLotus Domino8.0.2.2*******
    2.3ApplicationIbmLotus Domino8.0.2.3*******
    2.3ApplicationIbmLotus Domino8.0.2.4*******
    2.3ApplicationIbmLotus Domino8.0.2.5*******
    2.3ApplicationIbmLotus Domino8.0.2.6*******
    2.3ApplicationIbmLotus Domino8.5.0*******
    2.3ApplicationIbmLotus Domino8.5.0.1*******
    2.3ApplicationIbmLotus Domino8.5.1*******
    2.3ApplicationIbmLotus Domino8.5.1.1*******
    2.3ApplicationIbmLotus Domino8.5.1.2*******
    2.3ApplicationIbmLotus Domino8.5.1.3*******
    2.3ApplicationIbmLotus Domino8.5.1.4*******
    2.3ApplicationIbmLotus Domino8.5.1.5*******
    2.3ApplicationIbmLotus Domino8.5.2*******
    2.3ApplicationIbmLotus Domino8.5.2.1*******
    2.3ApplicationIbmLotus Domino8.5.2.2*******
    2.3ApplicationIbmLotus Domino8.5.3*******

Vulnerable Software List

VendorProductVersions
Ibm Lotus Domino 7.0, 7.0.1, 7.0.1.1, 7.0.2, 7.0.2.1, 7.0.2.2, 7.0.2.3, 7.0.3, 7.0.3.1, 7.0.4, 7.0.4.1, 7.0.4.2, 8.0, 8.0.1, 8.0.2, 8.0.2.1, 8.0.2.2, 8.0.2.3, 8.0.2.4, 8.0.2.5, 8.0.2.6, 8.5.0, 8.5.0.1, 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.1.3, 8.5.1.4, 8.5.1.5, 8.5.2, 8.5.2.1, 8.5.2.2, 8.5.3

References

NameSourceURLTags
43860http://secunia.com/advisories/43860SECUNIAVendor Advisory
8164http://securityreason.com/securityalert/8164SREASON
1025241http://securitytracker.com/id?1025241SECTRACK
20110322 ZDI-11-110: (0day) IBM Lotus Domino Server Controller Authentication Bypass Remote Code Execution Vulnerabilityhttp://www.securityfocus.com/archive/1/517119/100/0/threadedBUGTRAQ
46985http://www.securityfocus.com/bid/46985BID
ADV-2011-0758http://www.vupen.com/english/advisories/2011/0758VUPENVendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-11-110http://www.zerodayinitiative.com/advisories/ZDI-11-110MISC