CVE-2009-5033
published 2010-12-16CVE-2009-5033: IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, which allows remote authenticated users…
PriorityP416medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
0.99%
58.5th percentile
IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, which allows remote authenticated users to obtain access to other users' data via a sync operation, related to storage of the data of multiple users within the same thread.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | lotus_notes_traveler | <= 8.5.0.1 | — |
| ibm | lotus_notes_traveler | — | — |
| ibm | lotus_notes_traveler | — | — |
| ibm | lotus_notes_traveler | — | — |
| ibm | lotus_notes_traveler | — | — |
| ibm | lotus_notes_traveler | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg24019529&aid=1http://www-1.ibm.com/support/docview.wss?uid=swg1LO41040http://www-10.lotus.com/ldd/dominowiki.nsf/page.xsp?documentId=A6604E906E0DF2DF8525778B005D4466&action=openDocumenthttps://exchange.xforce.ibmcloud.com/vulnerabilities/64742http://www-01.ibm.com/support/docview.wss?uid=swg24019529&aid=1http://www-1.ibm.com/support/docview.wss?uid=swg1LO41040http://www-10.lotus.com/ldd/dominowiki.nsf/page.xsp?documentId=A6604E906E0DF2DF8525778B005D4466&action=openDocumenthttps://exchange.xforce.ibmcloud.com/vulnerabilities/64742
2010-12-16
Published