First published: Fri Oct 31 2008(Updated: )
IBM Lotus Connections 2.x before 2.0.1 stores the password for the administrative user in the trace.log file, which allows local users to obtain sensitive information by reading this file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Connections | <=2.0 | |
IBM Lotus Connections | =1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4807 is classified as a high severity vulnerability due to the exposure of sensitive administrative passwords.
To fix CVE-2008-4807, upgrade IBM Lotus Connections to version 2.0.1 or later to prevent the storage of passwords in the trace.log file.
CVE-2008-4807 affects users of IBM Lotus Connections versions prior to 2.0.1 and specifically version 1.0.2.
CVE-2008-4807 exposes sensitive administrative user passwords that are stored in the trace.log file.
Yes, local users can exploit CVE-2008-4807 by accessing the trace.log file to obtain the sensitive administrative passwords.