CVE-2001-1567
Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request with a large number of "+" characters before the .nsf…
Does this matter?
Lower severity and a low EPSS score (1.56%). Track it; it rarely justifies an emergency change on its own.
Description
Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request with a large number of "+" characters before the .nsf file extension, which are converted to spaces by Domino.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.56% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- ibm/lotus domino · ibm/lotus domino server
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=101284222932568&w=2
- http://marc.info/?l=bugtraq&m=101285903120879&w=2
- http://marc.info/?l=bugtraq&m=101286525008089&w=2
- http://www.iss.net/security_center/static/8072.php
- http://www.nextgenss.com/papers/hpldws.pdfVendor Advisory
- http://www.securityfocus.com/bid/4022
- http://marc.info/?l=bugtraq&m=101284222932568&w=2
- http://marc.info/?l=bugtraq&m=101285903120879&w=2
- http://marc.info/?l=bugtraq&m=101286525008089&w=2
- http://www.iss.net/security_center/static/8072.php
- http://www.nextgenss.com/papers/hpldws.pdfVendor Advisory
- http://www.securityfocus.com/bid/4022
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.