Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-0304


The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, aka SPR KLYHA7MM3J. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0920.


Published

2016-06-29T01:59:06.840

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 8.1 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm domino 8.5.3 Yes
Application ibm domino 8.5.3.1 Yes
Application ibm domino 8.5.3.2 Yes
Application ibm domino 8.5.3.3 Yes
Application ibm domino 8.5.3.4 Yes
Application ibm domino 8.5.3.5 Yes
Application ibm domino 8.5.3.6 Yes
Application ibm domino 8.5.2 Yes
Application ibm domino 8.5.2.1 Yes
Application ibm domino 8.5.2.2 Yes
Application ibm domino 8.5.2.3 Yes
Application ibm domino 8.5.2.4 Yes
Application ibm domino 8.5.1 Yes
Application ibm domino 8.5.1.1 Yes
Application ibm domino 8.5.1.2 Yes
Application ibm domino 8.5.1.3 Yes
Application ibm domino 8.5.1.4 Yes
Application ibm domino 8.5.1.5 Yes
Application ibm domino 8.5.0 Yes
Application ibm domino 9.0.1 Yes
Application ibm domino 9.0.1.1 Yes
Application ibm domino 9.0.1.2 Yes
Application ibm domino 9.0.1.3 Yes
Application ibm domino 9.0.1.4 Yes
Application ibm domino 9.0.1.5 Yes

References