Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

APP:IBM:DOMINO-BYPASS-1

Severity

Major

Recommended

Yes

Recommended Action

Drop

Category

APP

Keywords

IBM Lotus Domino Remote Console Auth Bypass

Release Date

2015/01/07

Update Number

2457

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

APP: IBM Lotus Domino Remote Console Auth Bypass


This signature detects attempts to exploit a known vulnerability against IBM Lotus Domino. Attackers could bypass security restrictions to gain unauthorized access to user accounts and execute arbitrary code.

Extended Description

The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.

Affected Products

  • Ibm lotus_domino 7.0
  • Ibm lotus_domino 7.0.1
  • Ibm lotus_domino 7.0.1.1
  • Ibm lotus_domino 7.0.2
  • Ibm lotus_domino 7.0.2.1
  • Ibm lotus_domino 7.0.2.2
  • Ibm lotus_domino 7.0.2.3
  • Ibm lotus_domino 7.0.3
  • Ibm lotus_domino 7.0.3.1
  • Ibm lotus_domino 7.0.4
  • Ibm lotus_domino 7.0.4.1
  • Ibm lotus_domino 7.0.4.2
  • Ibm lotus_domino 8.0
  • Ibm lotus_domino 8.0.1
  • Ibm lotus_domino 8.0.2
  • Ibm lotus_domino 8.0.2.1
  • Ibm lotus_domino 8.0.2.2
  • Ibm lotus_domino 8.0.2.3
  • Ibm lotus_domino 8.0.2.4
  • Ibm lotus_domino 8.0.2.5
  • Ibm lotus_domino 8.0.2.6
  • Ibm lotus_domino 8.5.0
  • Ibm lotus_domino 8.5.0.1
  • Ibm lotus_domino 8.5.1
  • Ibm lotus_domino 8.5.1.1
  • Ibm lotus_domino 8.5.1.2
  • Ibm lotus_domino 8.5.1.3
  • Ibm lotus_domino 8.5.1.4
  • Ibm lotus_domino 8.5.1.5
  • Ibm lotus_domino 8.5.2
  • Ibm lotus_domino 8.5.2.1
  • Ibm lotus_domino 8.5.2.2
  • Ibm lotus_domino 8.5.3

References

  • BugTraq: 46985
  • CVE: CVE-2011-1519
  • URL: http://www-142.ibm.com/software/sw-lotus/products/product4.nsf/wdocs/dominohomepage

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out