Vulnerability Name: | CVE-2007-5701 (CCN-37372) | ||||||||
Assigned: | 2007-10-23 | ||||||||
Published: | 2007-10-23 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Incomplete blacklist vulnerability in the Certificate Authority (CA) in IBM Lotus Domino before 7.0.3 allows local users, or attackers with physical access, to obtain sensitive information (passwords) when an administrator enters a "ca activate" or "ca unlock" command with any uppercase character, which bypasses a blacklist designed to suppress password logging, resulting in cleartext password disclosure in the console log and Admin panel. | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-310 CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-5701 Source: OSVDB Type: UNKNOWN 40952 Source: CCN Type: SA27321 IBM Lotus Domino Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 27321 Source: CCN Type: IBM Technote (FAQ) 1261095 Potential security issue with Domino Certificate Authority (CA) process commands Source: CONFIRM Type: Patch http://www-1.ibm.com/support/docview.wss?uid=swg21261095 Source: CCN Type: OSVDB ID: 40952 IBM Lotus Domino Certificate Authority (CA) Local Cleartext Password Disclosure Source: BID Type: Patch 26176 Source: CCN Type: BID-26176 IBM Lotus Domino Information Disclosure Vulnerabilities and Buffer Overflow Vulnerability Source: VUPEN Type: UNKNOWN ADV-2007-3598 Source: XF Type: UNKNOWN domino-ca-password-disclosure(37372) Source: XF Type: UNKNOWN domino-ca-password-disclosure(37372) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |