Lotus Domino 5.0.9a and earlier, even when configured with the DominoNoBanner=1 option, allows remote attackers to obtain potential sensitive information such as the version via a request for a non-existent .nsf database, which leaks the version in the HTTP banner.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Domino | Lotus | 5.0.8 (including) | 5.0.8 (including) |
Domino | Lotus | 5.0.9 (including) | 5.0.9 (including) |
Domino | Lotus | 5.0.9a (including) | 5.0.9a (including) |