CVE-1999-0429: High severity IBM Lotus Notes vulnerability
The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable the 'Encrypt Saved Mail' preference in the IBM/Lotus Notes 4.5 client so that saved copies of encrypted mail are stored encrypted and not transmitted in clear across the network.
IBM/Lotus Notes 4.5 client Encrypt Saved Mail = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0429?
CVE-1999-0429 is considered a moderate vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-1999-0429?
To fix CVE-1999-0429, ensure that the 'Encrypt Saved Mail' preference is enabled in the Lotus Notes 4.5 client settings.
What types of data are affected by CVE-1999-0429?
CVE-1999-0429 affects encrypted mail sent by the Lotus Notes 4.5 client when the encryption preference is not set.
Can CVE-1999-0429 be exploited remotely?
CVE-1999-0429 can be exploited over the network if the mail is sent without encryption, allowing potential interception.
Who is impacted by CVE-1999-0429?
Users of Lotus Notes 4.5 are impacted by CVE-1999-0429 if they do not configure their mail encryption settings properly.