First published: Sat Mar 31 2007(Updated: )
The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL libraries and execute arbitrary code via arbitrary arguments to the loadLibrary function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sametime | <=7.0 | |
IBM Sametime | =7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1784 has a high severity rating due to its ability to allow remote attackers to execute arbitrary code on the affected systems.
To fix CVE-2007-1784, update your IBM Lotus Sametime to version 7.5 or later, as this version addresses the vulnerability.
CVE-2007-1784 affects IBM Lotus Sametime versions prior to 7.5, including all versions up to and including 7.0.
CVE-2007-1784 can be exploited by remote attackers who can pass arbitrary arguments to the loadLibrary function in the JNILoader ActiveX control.
As a temporary workaround for CVE-2007-1784, consider disabling or removing the JNILoader ActiveX control in affected versions of IBM Lotus Sametime until a proper update can be applied.