First published: Fri Apr 12 2002(Updated: )
Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes API call (NSFDbReadObject) that directly accesses the object.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Domino Server | =5 | |
IBM Lotus Domino Server | =4.5 | |
IBM Lotus Domino Server | =4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0037 has a moderate severity rating, allowing unauthorized access to documents.
To fix CVE-2002-0037, upgrade to a version of Lotus Domino Server that is not affected by the vulnerability.
CVE-2002-0037 affects Lotus Domino Servers 5.x, 4.6x, and 4.5x.
CVE-2002-0037 allows attackers to bypass Reader and Author access control lists via an API call.
Organizations using IBM Lotus Domino Server versions 4.5, 4.6, or 5.x are at risk from CVE-2002-0037.