Vulnerability CVE-2008-7253


Published: 2010-01-25   Modified: 2012-02-12

Description:
The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.

Type:

CWE-16

(Configuration)

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
IBM -> Lotus domino server 

 References:
http://www.kb.cert.org/vuls/id/867593
http://www.kb.cert.org/vuls/id/AAMN-5K42VT
http://www.kb.cert.org/vuls/id/AAMN-5K42VN
http://www-01.ibm.com/support/docview.wss?&uid=swg21201202

Copyright 2024, cxsecurity.com

 

Back to Top