CVE-2007-5701
Summary
| CVE | CVE-2007-5701 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-10-29 21:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Incomplete blacklist vulnerability in the Certificate Authority (CA) in IBM Lotus Domino before 7.0.3 allows local users, or attackers with physical access, to obtain sensitive information (passwords) when an administrator enters a "ca activate" or "ca unlock" command with any uppercase character, which bypasses a blacklist designed to suppress password logging, resulting in cleartext password disclosure in the console log and Admin panel. |
Risk And Classification
Primary CVSS: v2.0 2.1 from [email protected]
AV:L/AC:L/Au:N/C:P/I:N/A:N
Problem Types: CWE-200 | CWE-310 | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Lotus Domino | 6.5.5 | All | All | All |
| Application | Ibm | Lotus Domino | 6.5.5 | All | fp1 | All |
| Application | Ibm | Lotus Domino | 6.5.5 | All | fp2 | All |
| Application | Ibm | Lotus Domino | 6.5.5 | All | fp3 | All |
| Application | Ibm | Lotus Domino | 6.5.6 | All | All | All |
| Application | Ibm | Lotus Domino | 6.5.6 | All | fp1 | All |
| Application | Ibm | Lotus Domino | 7.0 | All | All | All |
| Application | Ibm | Lotus Domino | 7.0.2 | All | All | All |
| Application | Ibm | Lotus Domino | 7.0.2 | All | fp1 | All |
| Application | Ibm | Lotus Domino | 7.0.2 | All | fp2 | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/40952 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| IBM Lotus Domino Information Disclosure Vulnerabilities and Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| IBM Lotus Domino Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.