CVE Vulnerabilities

CVE-2001-1567

Published: Dec 31, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request with a large number of + characters before the .nsf file extension, which are converted to spaces by Domino.

Affected Software

NameVendorStart VersionEnd Version
Lotus_dominoIbm5.0 (including)5.0 (including)
Lotus_dominoIbm5.0.1 (including)5.0.1 (including)
Lotus_dominoIbm5.0.2 (including)5.0.2 (including)
Lotus_dominoIbm5.0.3 (including)5.0.3 (including)
Lotus_dominoIbm5.0.4 (including)5.0.4 (including)
Lotus_dominoIbm5.0.5 (including)5.0.5 (including)
Lotus_dominoIbm5.0.6 (including)5.0.6 (including)
Lotus_dominoIbm5.0.7 (including)5.0.7 (including)
Lotus_dominoIbm5.0.7a (including)5.0.7a (including)
Lotus_dominoIbm5.0.8 (including)5.0.8 (including)
Lotus_dominoIbm5.0.9 (including)5.0.9 (including)
Lotus_domino_serverIbm*5.0.9a (including)

References