CVE-2013-0127: Medium severity ibm notes vulnerability
IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote attackers to bypass intended restrictions on Java code execution and X-Confirm-Reading-To functionality via a crafted message, aka SPRs JMOY95BLM6 and JMOY95BN49.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0127?
CVE-2013-0127 has been rated as important due to its potential to allow remote code execution.
How do I fix CVE-2013-0127?
To fix CVE-2013-0127, upgrade to IBM Lotus Notes version 8.5.3 FP4 Interim Fix 1 or 9.0 Interim Fix 1.
What vulnerabilities are associated with CVE-2013-0127?
CVE-2013-0127 allows attackers to bypass restrictions on Java code execution and X-Confirm-Reading-To functionality.
Which versions of IBM Lotus Notes are affected by CVE-2013-0127?
CVE-2013-0127 affects IBM Lotus Notes versions 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1.
What type of attack does CVE-2013-0127 facilitate?
CVE-2013-0127 facilitates remote attacks that exploit unblocked APPLET elements in HTML e-mails.