VulnerabilityModified
CVE-2010-1487
IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, aka SPR JSTN837SEG.
LOW 2.1EPSS 0.35%
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, aka SPR JSTN837SEG.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- ibm/lotus notes
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/39507Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21427073
- http://www.securityfocus.com/bid/39525
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14725
- http://secunia.com/advisories/39507Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21427073
- http://www.securityfocus.com/bid/39525
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14725
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.