Oval Definition:oval:org.mitre.oval:def:14348
Revision Date:2015-06-15Version:7
Title:Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL file, aka SPR PRAD82YJW2.
Description:Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL file, aka SPR PRAD82YJW2.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2011-0912
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Lotus Notes
Definition Synopsis
  • Determine if the version of Lotus Notes is less than or equal to 8.5.1.4 and is greater than or equal to 8.0.1
  • IBM Lotus Notes is installed
  • AND Determine if the version of Lotus Notes is less than or equal to 8.5.1.4
  • AND Determine if the version of Lotus Notes is greater than or equal to 8.0.1
  • BACK