CVE-2000-0022: Medium severity Lotus Domino Server vulnerability
Lotus Domino HTTP server does not properly disable anonymous access for the cgi-bin directory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable anonymous access for the cgi-bin directory in the Lotus Domino HTTP server configuration so that anonymous users cannot access CGI scripts.
Lotus Domino HTTP server anonymous access for the cgi-bin directory = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0022?
CVE-2000-0022 is considered a high severity vulnerability due to the potential for unauthorized access to sensitive resources.
How do I fix CVE-2000-0022?
To fix CVE-2000-0022, ensure that anonymous access is properly disabled in the cgi-bin directory of the Lotus Domino HTTP server.
What is the impact of CVE-2000-0022?
The impact of CVE-2000-0022 includes the risk of unauthorized users exploiting the CGI scripts to access restricted data.
Which versions of Lotus Domino Server are affected by CVE-2000-0022?
CVE-2000-0022 affects IBM Lotus Domino Server version 4.6 and 4.6.x.
What is the default configuration risk associated with CVE-2000-0022?
The default configuration risk associated with CVE-2000-0022 is that it may allow unintended anonymous access to sensitive scripts and backend functions.