First published: Wed Jun 06 2007(Updated: )
IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Domino | =7.0 | |
IBM Lotus Domino | =7.0.2 | |
IBM Lotus Domino | =7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0068 has a medium severity rating due to its potential to allow privilege escalation for remote authenticated users.
To resolve CVE-2007-0068, upgrade IBM Lotus Domino to version 7.0.3 or later where the issue has been addressed.
Users of IBM Lotus Domino versions 7.0, 7.0.1, and 7.0.2 are impacted by CVE-2007-0068.
CVE-2007-0068 allows remote authenticated users to gain elevated privileges by exploiting a flaw in agent signature revalidation.
Yes, CVE-2007-0068 can be exploited by remote authenticated users through a modified agent in a server database.