CVE-2008-0862: Medium severity ibm notes vulnerability
Published Feb 21, 2008
·Updated
IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email message to another user, which allows user-assisted remote attackers to bypass Execution Control List (ECL) protection.
Affected Software
4 affected components
IBM Lotus Notes=6.0
IBM Lotus Notes=7.0
IBM Lotus Notes=6.5
IBM Lotus Notes=8.0
Event History
Feb 21, 2008
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0862?
CVE-2008-0862 is generally considered to have a moderate severity due to its potential for user-assisted exploitation.
2
How do I fix CVE-2008-0862?
To fix CVE-2008-0862, users should update to a patched version of IBM Lotus Notes that addresses this vulnerability.
3
Which versions of IBM Lotus Notes are affected by CVE-2008-0862?
CVE-2008-0862 affects IBM Lotus Notes versions 6.0, 6.5, 7.0, and 8.0.
4
What type of attack does CVE-2008-0862 involve?
CVE-2008-0862 allows user-assisted remote attackers to bypass Execution Control List (ECL) protection.
5
Can CVE-2008-0862 be exploited without user interaction?
No, CVE-2008-0862 requires user interaction to exploit, making it a user-assisted vulnerability.