IBM Lotus Domino WebMail Information Disclosure Vulnerability
BID:14388
Info
IBM Lotus Domino WebMail Information Disclosure Vulnerability
| Bugtraq ID: | 14388 |
| Class: | Design Error |
| CVE: |
CVE-2005-2428 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2005 12:00AM |
| Updated: | Feb 14 2007 11:47PM |
| Credit: | Discovery is credited to Leandro Meiners <[email protected]>. |
| Vulnerable: |
IBM Lotus Domino Enterprise Server 6.5.4 IBM Lotus Domino Enterprise Server 6.5.2 IBM Lotus Domino Enterprise Server 6.0.5 IBM Lotus Domino Enterprise Server 6.0.1 IBM Lotus Domino Enterprise Server 5.0.13 IBM Lotus Domino Enterprise Server 5.0.12 IBM Lotus Domino Enterprise Server 5.0.9 IBM Lotus Domino Enterprise Server 5.0.3 IBM Lotus Domino 6.5.4 IBM Lotus Domino 6.5.3 IBM Lotus Domino 6.5.2 IBM Lotus Domino 6.5.1 IBM Lotus Domino 6.5 .0 IBM Lotus Domino 6.0.5 IBM Lotus Domino 6.0.4 IBM Lotus Domino 6.0.4 IBM Lotus Domino 6.0.3 IBM Lotus Domino 6.0.2 CF2 IBM Lotus Domino 6.0.2 IBM Lotus Domino 6.0.1 IBM Lotus Domino 6.0 IBM Lotus Domino 5.0.13 |
| Not Vulnerable: | |
Discussion
IBM Lotus Domino WebMail Information Disclosure Vulnerability
IBM Lotus Domino WebMail is affected by an information-disclosure vulnerability.
An attacker can obtain a user's password hash. and then carry out brute-force attacks to crack the password and gain access to the user's account.
Further reports indicate that an attacker can use Lotus Notes Client to view the address book and retrieve the password hashes.
IBM Lotus Domino WebMail is affected by an information-disclosure vulnerability.
An attacker can obtain a user's password hash. and then carry out brute-force attacks to crack the password and gain access to the user's account.
Further reports indicate that an attacker can use Lotus Notes Client to view the address book and retrieve the password hashes.
Exploit / POC
IBM Lotus Domino WebMail Information Disclosure Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
IBM Lotus Domino WebMail Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
IBM Lotus Domino WebMail Information Disclosure Vulnerability
References:
References:
- Lotus Domino Product Homepage (IBM)
- CYBSEC - Security Advisory: Default Configuration Information Disclosure in Lotu (Leandro Meiners
) - IBM Lotus Notes multiple disclosures of password hashes ("Shalom Carmel"
)