CVE-2011-1519: Critical severity ibm lotus domino mail server vulnerability
The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1519?
CVE-2011-1519 is categorized as a high severity vulnerability that allows attackers to bypass authentication.
How do I fix CVE-2011-1519?
To mitigate CVE-2011-1519, ensure that the server does not allow UNC share pathnames specified by clients.
What versions of IBM Lotus Domino are affected by CVE-2011-1519?
CVE-2011-1519 affects IBM Lotus Domino versions 7.x and 8.x, specifically from versions 7.0 to 8.5.1.
Can CVE-2011-1519 allow remote code execution?
Yes, CVE-2011-1519 can enable remote attackers to execute arbitrary code on the affected systems.
What is the cause of CVE-2011-1519?
CVE-2011-1519 is caused by the remote console in IBM Lotus Domino improperly verifying credentials against a user-specified UNC share.