Vulnerability Name: | CVE-2007-0977 (CCN-32595) | ||||||||
Assigned: | 2007-02-13 | ||||||||
Published: | 2007-02-13 | ||||||||
Updated: | 2017-10-11 | ||||||||
Summary: | IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view, a different vector than CVE-2005-2428. "Generate HTML for all fields" must be enabled for successful exploitation. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 7.1 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N) 6.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N/E:F/RL:U/RC:UR)
2.3 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:F/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-0977 Source: OSVDB Type: UNKNOWN 35764 Source: CCN Type: IBM Lotus Domino Web site IBM business collaboration software - Lotus Domino Source: CCN Type: OSVDB ID: 35764 IBM Lotus Domino / WebMail names.nsf User HTTPPassword Hashes Disclosure Source: XF Type: UNKNOWN domino-names-information-disclosure(32595) Source: EXPLOIT-DB Type: UNKNOWN 3302 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |