Vulnerability Name: | CVE-2009-3114 (CCN-53101) | ||||||||
Assigned: | 2009-09-08 | ||||||||
Published: | 2009-09-08 | ||||||||
Updated: | 2018-10-10 | ||||||||
Summary: | The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer's Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:TF/RC:C)
3.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:TF/RC:C)
| ||||||||
Vulnerability Type: | CWE-94 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Sep 08 2009 - 05:26:26 CDT IBM Lotus Notes 8.5 RSS Widget Privilege Escalation Source: MITRE Type: CNA CVE-2009-3114 Source: CCN Type: SA36813 IBM Lotus Notes RSS Widget Internet Zone Security Bypass Source: SECUNIA Type: Vendor Advisory 36813 Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21403834 Source: CCN Type: IBM Web site Lotus Notes Source: CCN Type: OSVDB ID: 57935 IBM Lotus Notes RSS Reader Widget MSIE Local Machine Zone Arbitrary Script Execution Source: MISC Type: UNKNOWN http://www.scip.ch/?vuldb.4021 Source: BUGTRAQ Type: UNKNOWN 20090908 [scip_Advisory 4021] IBM Lotus Notes 8.5 RSS Widget Privilege Escalation Source: BID Type: UNKNOWN 36305 Source: CCN Type: BID-36305 IBM Lotus Notes RSS Reader Widget HTML Injection Vulnerability Source: XF Type: UNKNOWN lotusnotes-rss-xss(53101) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |