This application requires Javascript for optimal performance.

IBM.Lotus.Domino.Server.Controller.Authentication.Bypass

Release Date

Jan 05, 2012

Severity

medium

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates a possible attempt to exploit an Authentication Bypass vulnerability in the IBM Lotus Domino Server Controller.

The vulnerability is due to the vulnerable application fails to adequately validate user-supplied data. Remote attackers may exploit this vulnerability to log in as any user without authentication.

Affected Products

IBM Lotus Domino Server Controller 8.5.3
IBM Lotus Domino Server Controller 8.5.2 FP3

Recommended Actions

Upgrade to latest version when available.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-1519

Reference/s

http://www.exploit-db.com/exploits/18179/
http://dsecrg.com/files/pub/pdf/Lotus%20Domino%20Server%20Controller%20service%20is%20under%20attack.pdf

Reference: VID-30520