Описание
IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive information, or inject Lotus Script or other character sequences into a session.
Ссылки
- Broken LinkPatchVendor Advisory
- Broken LinkPatch
- Broken LinkThird Party AdvisoryVDB Entry
- Not Applicable
- Permissions Required
- Broken LinkPatchVendor Advisory
- Broken LinkPatch
- Broken LinkThird Party AdvisoryVDB Entry
- Not Applicable
- Permissions Required
Уязвимые конфигурации
Конфигурация 1Версия до 6.5.5 (исключая)Версия от 7.0 (включая) до 7.0.2 (исключая)Версия до 6.5.5 (включая)Версия от 7.0.0 (включая) до 7.0.3 (исключая)
Одно из
cpe:2.3:a:ibm:lotus_domino:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:6.5.5:-:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:7.0.2:-:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_notes:*:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00089
Низкий
7.8 High
CVSS3
6.2 Medium
CVSS2
Дефекты
CWE-732
Связанные уязвимости
CVSS3: 7.8
github
почти 4 года назад
IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive information, or inject Lotus Script or other character sequences into a session.
EPSS
Процентиль: 25%
0.00089
Низкий
7.8 High
CVSS3
6.2 Medium
CVSS2
Дефекты
CWE-732