CVE-2008-7286: Input Validation
Published Mar 22, 2011
·Updated
IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino does not properly handle URLs that request images, which allows remote authenticated users to cause a denial of service (daemon crash) via a request to resources.nsf, aka SPR XFXF7JDBCX.
Affected Software
2 affected components
IBM Lotus Quickr=8.1
IBM Lotus Domino
Event History
Mar 22, 2011
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
05:55 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-7286?
CVE-2008-7286 is classified as a moderate severity vulnerability that can lead to a denial of service.
2
How do I fix CVE-2008-7286?
To fix CVE-2008-7286, upgrade IBM Lotus Quickr to version 8.1.0.2 or later.
3
Who is affected by CVE-2008-7286?
Only users of IBM Lotus Quickr 8.1 prior to version 8.1.0.2 are affected by CVE-2008-7286.
4
What type of attack does CVE-2008-7286 facilitate?
CVE-2008-7286 allows authenticated remote users to initiate a denial of service attack by crashing the daemon.
5
What component of IBM products is primarily impacted by CVE-2008-7286?
CVE-2008-7286 primarily impacts the services for Lotus Domino in IBM Lotus Quickr.