IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a clients Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows remote attackers to obtain a users privileges by intercepting the LtpaToken cookie.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lotus_domino_web_access | Ibm | 7.0.1 (including) | 7.0.1 (including) |