First published: Mon Jun 12 2017(Updated: )
IBM iNotes 8.5 and 9.0 could allow a remote attacker to send a malformed email to a victim, that when opened could cause an information disclosure. IBM X-Force ID: 123854.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus iNotes | =8.5.0.0 | |
IBM Lotus iNotes | =8.5.0.1 | |
IBM Lotus iNotes | =8.5.1.0 | |
IBM Lotus iNotes | =8.5.1.1 | |
IBM Lotus iNotes | =8.5.1.2 | |
IBM Lotus iNotes | =8.5.1.3 | |
IBM Lotus iNotes | =8.5.1.4 | |
IBM Lotus iNotes | =8.5.1.5 | |
IBM Lotus iNotes | =8.5.2.0 | |
IBM Lotus iNotes | =8.5.2.1 | |
IBM Lotus iNotes | =8.5.2.2 | |
IBM Lotus iNotes | =8.5.2.3 | |
IBM Lotus iNotes | =8.5.3.0 | |
IBM Lotus iNotes | =8.5.3.1 | |
IBM Lotus iNotes | =8.5.3.2 | |
IBM Lotus iNotes | =8.5.3.3 | |
IBM Lotus iNotes | =8.5.3.4 | |
IBM Lotus iNotes | =8.5.3.5 | |
IBM Lotus iNotes | =9.0.0.0 | |
IBM Lotus iNotes | =9.0.1.0 | |
IBM Lotus iNotes | =9.0.1.1 | |
IBM Lotus iNotes | =9.0.1.2 | |
IBM Lotus iNotes | =9.0.1.3 | |
IBM Lotus iNotes | =9.0.1.4 | |
IBM Lotus iNotes | =9.0.1.5 | |
IBM Lotus iNotes | =9.0.1.6 | |
IBM Lotus iNotes | =9.0.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1214 has a medium severity level due to the potential for information disclosure via a malicious email.
To fix CVE-2017-1214, users should apply the latest updates and patches provided by IBM for iNotes.
IBM iNotes versions 8.5 and 9.0, including their various sub-versions, are affected by CVE-2017-1214.
CVE-2017-1214 allows attackers to send malformed emails that can lead to information disclosure when opened by the user.
Users are advised to be cautious with opening emails from unknown sources and ensure their iNotes software is up to date.