IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive information, or inject Lotus Script or other character sequences into a session.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lotus_domino | Ibm | * | 6.5.5 (excluding) |
Lotus_domino | Ibm | 7.0 (including) | 7.0.2 (excluding) |
Lotus_domino | Ibm | 6.5.5 (including) | 6.5.5 (including) |
Lotus_domino | Ibm | 7.0.2 (including) | 7.0.2 (including) |
Lotus_notes | Ibm | * | 6.5.5 (including) |
Lotus_notes | Ibm | 7.0.0 (including) | 7.0.3 (excluding) |