First published: Thu Jan 08 2004(Updated: )
Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Domino R5 | =6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0029 is considered a high severity vulnerability due to its potential to allow local users to gain unauthorized privileges in Lotus Notes Domino.
To fix CVE-2004-0029, change the permissions of the notes.ini file to restrict write access only to authorized users.
CVE-2004-0029 specifically affects IBM Lotus Domino version 6.0.2 running on Linux.
The impact of CVE-2004-0029 allows local users to modify the Notes configuration, potentially leading to privilege escalation and system compromise.
While CVE-2004-0029 is an older vulnerability, it remains relevant for organizations still using unsupported versions of Lotus Domino.