IBM Lotus Notes contains a flaw that is triggered when the URL handler fails to properly handle notes:// URLs. This may allow a context-dependent attacker to execute arbitrary code.
Classification
Location:
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Patch / RCS
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Third-party Verified
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, IBM has released a patch to address this vulnerability. Check the vendor advisory or solution in the references section. This patch is "available upon request by opening a service request with IBM Support."