First published: Mon Dec 31 2001(Updated: )
Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automatically executed when the user processes the e-mail message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Notes | =4.6 | |
IBM Notes | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1504 is classified as a critical vulnerability allowing remote command execution.
To resolve CVE-2001-1504, upgrade Lotus Notes to a version later than 5.0 that addresses this vulnerability.
CVE-2001-1504 affects IBM Lotus Notes versions 4.6 and 5.0.
CVE-2001-1504 involves executing arbitrary commands through a malicious Lotus Notes object embedded in an email.
Using Lotus Notes 4.6 is unsafe due to CVE-2001-1504, and it is highly recommended to upgrade to a patched version.