| Vulnerability Name: | CVE-2008-7253 (CCN-55965) | ||||||||
| Assigned: | 2008-02-22 | ||||||||
| Published: | 2008-02-22 | ||||||||
| Updated: | 2010-01-26 | ||||||||
| Summary: | The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.9 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:H/RL:W/RC:UR)
3.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:H/RL:W/RC:UR)
| ||||||||
| Vulnerability Type: | CWE-16 | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-2008-7253 Source: CCN Type: IBM Technote (FAQ) 1201202 How to enable or disable HTTP methods Source: CONFIRM Type: UNKNOWN http://www-01.ibm.com/support/docview.wss?&uid=swg21201202 Source: CCN Type: US-CERT VU#867593 Web servers enable HTTP TRACE method by default Source: CERT-VN Type: US Government Resource VU#867593 Source: CONFIRM Type: UNKNOWN http://www.kb.cert.org/vuls/id/AAMN-5K42VN Source: CONFIRM Type: UNKNOWN http://www.kb.cert.org/vuls/id/AAMN-5K42VT Source: CCN Type: IBM Lotus Domino Web site IBM Software - IBM Lotus Domino - Product Overview Source: XF Type: UNKNOWN lotus-domino-server-xst(55965) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||