First published: Mon Jan 25 2010(Updated: )
The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Domino Server | =7.0 | |
IBM Lotus Domino Server | =6.0 | |
IBM Lotus Domino Server | =6.5 | |
IBM Lotus Domino Server | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-7253 is considered a medium severity vulnerability due to its potential for cross-site tracing attacks that could compromise user credentials.
To fix CVE-2008-7253, disable the HTTP TRACE method in the IBM Lotus Domino Server configuration.
CVE-2008-7253 affects IBM Lotus Domino Server versions 6.0, 6.5, 7.0, and 8.0.
CVE-2008-7253 enables cross-site tracing (XST) attacks, allowing attackers to steal cookies and session credentials.
As a temporary workaround for CVE-2008-7253, ensure that the HTTP TRACE method is disabled in the settings until a permanent fix can be applied.