CVE-2002-0408: Medium severity lotus domino vulnerability
htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version number of the server via a request that generates an HTTP 500 error code, which leaks the version in a hard-coded error message.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0408?
The severity of CVE-2002-0408 is considered to be high due to the potential for information disclosure.
How do I fix CVE-2002-0408?
To fix CVE-2002-0408, upgrade Lotus Domino to version 5.0.9b or later where the vulnerability is addressed.
What type of attack does CVE-2002-0408 facilitate?
CVE-2002-0408 facilitates information disclosure attacks by revealing the server version through error messages.
Which versions of Lotus Domino are affected by CVE-2002-0408?
Lotus Domino versions 5.0.9a and earlier are affected by CVE-2002-0408.
What impact does CVE-2002-0408 have on security?
CVE-2002-0408 can allow attackers to gain insights about the server's software version, potentially aiding in further exploitation.