IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138708.
2018-02-19T14:29:00.583
2024-11-21T03:59:45.860
Modified
CVSSv3.0: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | notes | 8.5.1.5 | Yes |
Application | ibm | notes | 8.5.2.4 | Yes |
Application | ibm | notes | 8.5.3.6 | Yes |
Application | ibm | notes | 9.0 | Yes |
Application | ibm | notes | 9.0.1.9 | Yes |
Application | ibm | client_application_access | 1.0.0.1 | Yes |
Application | ibm | client_application_access | 1.0.1 | Yes |
Application | ibm | client_application_access | 1.0.1.2 | Yes |