First published: Tue May 03 2005(Updated: )
HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicious applications.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Notes | =6.5.2 | |
IBM Lotus Notes | =6.0 | |
IBM Lotus Notes | =6.0.1 | |
IBM Lotus Notes | =6.0.2 | |
IBM Lotus Notes | =6.0.4 | |
IBM Lotus Notes | =6.5.1 | |
IBM Lotus Notes | =6.5 | |
IBM Lotus Notes | =6.5.3 | |
IBM Lotus Notes | =6.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1405 is considered to be of medium severity due to its potential to enable HTTP response splitting and cache poisoning attacks.
To fix CVE-2005-1405, upgrade to IBM Lotus Notes version 6.5.4 or later, or 6.0.5 or later.
CVE-2005-1405 affects IBM Lotus Notes versions 6.0 through 6.5.3.
CVE-2005-1405 is an HTTP response splitting vulnerability found in the @SetHTTPHeader function.
Yes, CVE-2005-1405 can be exploited remotely by attackers to poison the web cache.