CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:P/I:P/A:P
AI Score
Confidence
High
EPSS
Percentile
27.7%
IBM Lotus Notes 6.5.4 and 6.5.5, and 7.0.0 and 7.0.1, uses insecure default permissions (Everyone/Full Control) for the “Notes” folder and all children, which allows local users to gain privileges and modify, add, or delete files in that folder.
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | lotus_notes | 6.5.4 | cpe:2.3:a:ibm:lotus_notes:6.5.4:*:*:*:*:*:*:* |
ibm | lotus_notes | 6.5.5 | cpe:2.3:a:ibm:lotus_notes:6.5.5:*:*:*:*:*:*:* |
ibm | lotus_notes | 7.0.0 | cpe:2.3:a:ibm:lotus_notes:7.0.0:*:*:*:*:*:*:* |
ibm | lotus_notes | 7.0.1 | cpe:2.3:a:ibm:lotus_notes:7.0.1:*:*:*:*:*:*:* |
secunia.com/advisories/19537
secunia.com/advisories/27342
secunia.com/secunia_research/2005-29/advisory/
securitytracker.com/id?1017086
www-1.ibm.com/support/docview.wss?rs=463&uid=swg21246773
www.kb.cert.org/vuls/id/383092
www.osvdb.org/29761
www.securityfocus.com/archive/1/449126/100/0/threaded
www.securityfocus.com/bid/20612
www.vupen.com/english/advisories/2006/4093
exchange.xforce.ibmcloud.com/vulnerabilities/29660