CVE-2001-1504: High severity IBM Lotus Notes vulnerability
Published Dec 31, 2001
·Updated
Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automatically executed when the user processes the e-mail message.
Affected Software
2 affected components
IBM Lotus Notes=4.6
IBM Lotus Notes=5.0
Event History
Dec 31, 2001
CVE Published
05:00 AM
Jun 21, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1504?
CVE-2001-1504 is classified as a critical vulnerability allowing remote command execution.
2
How do I fix CVE-2001-1504?
To resolve CVE-2001-1504, upgrade Lotus Notes to a version later than 5.0 that addresses this vulnerability.
3
What types of software does CVE-2001-1504 affect?
CVE-2001-1504 affects IBM Lotus Notes versions 4.6 and 5.0.
4
What exploit does CVE-2001-1504 involve?
CVE-2001-1504 involves executing arbitrary commands through a malicious Lotus Notes object embedded in an email.
5
Can I still use Lotus Notes 4.6 safely despite CVE-2001-1504?
Using Lotus Notes 4.6 is unsafe due to CVE-2001-1504, and it is highly recommended to upgrade to a patched version.