CVE-2011-1519

The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field.  NOTE: this might overlap CVE-2011-0920.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
ibmlotus_domino
7.0
ibmlotus_domino
7.0.1
ibmlotus_domino
7.0.1.1
ibmlotus_domino
7.0.2
ibmlotus_domino
7.0.2.1
ibmlotus_domino
7.0.2.2
ibmlotus_domino
7.0.2.3
ibmlotus_domino
7.0.3
ibmlotus_domino
7.0.3.1
ibmlotus_domino
7.0.4
ibmlotus_domino
7.0.4.1
ibmlotus_domino
7.0.4.2
ibmlotus_domino
8.0
ibmlotus_domino
8.0.1
ibmlotus_domino
8.0.2
ibmlotus_domino
8.0.2.1
ibmlotus_domino
8.0.2.2
ibmlotus_domino
8.0.2.3
ibmlotus_domino
8.0.2.4
ibmlotus_domino
8.0.2.5
ibmlotus_domino
8.0.2.6
ibmlotus_domino
8.5.0
ibmlotus_domino
8.5.0.1
ibmlotus_domino
8.5.1
ibmlotus_domino
8.5.1.1
ibmlotus_domino
8.5.1.2
ibmlotus_domino
8.5.1.3
ibmlotus_domino
8.5.1.4
ibmlotus_domino
8.5.1.5
ibmlotus_domino
8.5.2
ibmlotus_domino
8.5.2.1
ibmlotus_domino
8.5.2.2
ibmlotus_domino
8.5.3
𝑥
= Vulnerable software versions