Lucene search

K
cve[email protected]CVE-2007-4309
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2007-4309

2022-10-0316:14:35
web.nvd.nist.gov
25
ibm
lotus notes
security
cve-2007-4309
administration
password management

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

5.9 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

69.5%

IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a different vulnerability than CVE-2005-2696.

Affected configurations

NVD
Node
ibmlotus_notesMatch5.0
OR
ibmlotus_notesMatch6.0
OR
ibmlotus_notesMatch7.0
OR
ibmlotus_notesMatch7.0.1
OR
ibmlotus_notesMatch7.0.2

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

5.9 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

69.5%