cbcvebase.
CVE-2007-4309
published 2007-08-13

CVE-2007-4309: IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1)…

PriorityP410low3.5CVSS 2.0
AVNACMAuSCPINAN
EPSS
0.85%
54.0th percentile
IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a different vulnerability than CVE-2005-2696.

Affected

5 ranges
VendorProductVersion rangeFixed in
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.