|
|
Info |
Last Modified |
| 11 months ago |
|
|
|
|
|
Description |
Lotus Notes contains a flaw that may allow a malicious user to manipulate application's files. The issue is triggered due to default permissions that grant "Everyone" group "Full Control" on the 'notes' directory and all child objects. It is possible that the flaw may allow arbitrary files manipulation resulting in a loss of integrity.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Authentication Management,
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
OSVDB:
Concern
|
|
Solution |
Upgrade to version 7.0.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
Lotus Notes
 |
6.5.4 |
6.5.5 |
6.5.6 |
7.0.0 |
7.0.1 |
|
|
|
|
Credit |
- Carsten Eiram - Secunia Research
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|