IBM Quickr Denial of Service and Security Bypass Vulnerabilities
BID:31608
Info
IBM Quickr Denial of Service and Security Bypass Vulnerabilities
| Bugtraq ID: | 31608 |
| Class: | Unknown |
| CVE: |
CVE-2008-4506 CVE-2008-4507 CVE-2008-4505 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | IBM |
| Vulnerable: |
IBM Lotus Quickr 8.1 Hotfix 5 IBM Lotus Quickr 8.1 Hotfix 15 IBM Lotus Quickr 8.1 IBM Lotus Quickr 8.0.0.2 Hotfix 11 IBM Lotus Quickr 8.0.0.2 IBM Lotus Quickr 8.0 |
| Not Vulnerable: |
IBM Lotus Quickr 8.1.0.1 |
Discussion
IBM Quickr Denial of Service and Security Bypass Vulnerabilities
IBM Quickr is prone to a denial-of-service vulnerability and security-bypass vulnerabilities.
Exploiting these issues can allow attackers to delete pages created by different authors, demote or delete 'place superuser' groups, or crash the affected application, resulting in denial-of-service conditions.
Versions prior to IBM Quickr 8.1.0.1 are vulnerable.
IBM Quickr is prone to a denial-of-service vulnerability and security-bypass vulnerabilities.
Exploiting these issues can allow attackers to delete pages created by different authors, demote or delete 'place superuser' groups, or crash the affected application, resulting in denial-of-service conditions.
Versions prior to IBM Quickr 8.1.0.1 are vulnerable.
Exploit / POC
IBM Quickr Denial of Service and Security Bypass Vulnerabilities
Attackers can use standard functionality to exploit the security-bypass issues. To exploit the denial-of-service issue, the attacker would likely use a browser.
Attackers can use standard functionality to exploit the security-bypass issues. To exploit the denial-of-service issue, the attacker would likely use a browser.
Solution / Fix
IBM Quickr Denial of Service and Security Bypass Vulnerabilities
Solution:
IBM has released Lotus Quickr 8.1.0.1 to address these issues. Please see the references for more information.
Solution:
IBM has released Lotus Quickr 8.1.0.1 to address these issues. Please see the references for more information.
References
IBM Quickr Denial of Service and Security Bypass Vulnerabilities
References:
References:
- IBM Homepage (IBM)
- Lotus Quickr (IBM)