CVE-2011-1519
published 2011-03-25CVE-2011-1519: The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by…
PriorityP262critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
9.20%
94.8th percentile
The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
| ibm | lotus_domino | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for authentication requests to the IBM Lotus Domino Server Controller remote console where the COOKIEFILE field contains a UNC share pathname (e.g., \\<remote_host>\<share>\<file>), indicating an attempt to redirect credential verification to an attacker-controlled file share. ↗
- →Alert on outbound SMB/CIFS connections (ports 139/445) originating from the Domino Server Controller process during authentication events, as exploitation causes the server to reach out to an attacker-controlled UNC path for credential file retrieval. ↗
- →Target IBM Lotus Domino versions 8.5.3 and 8.5.2 FP3 specifically when triaging exploitation attempts; these were confirmed vulnerable 0-day versions at time of disclosure. ↗
- ·The vulnerability affects both Domino 7.x and 8.x branches; detection and patching scope should cover both major version lines, not just 8.x. ↗
- ·This CVE may overlap with CVE-2011-0920; review both advisories to avoid duplicate or conflicting detection rules. ↗
- ·Exploitation was confirmed on Windows 7 and Windows 2008 hosts; Linux/Unix Domino deployments may behave differently regarding UNC path handling. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/43860http://securityreason.com/securityalert/8164http://securitytracker.com/id?1025241http://www.securityfocus.com/archive/1/517119/100/0/threadedhttp://www.securityfocus.com/bid/46985http://www.vupen.com/english/advisories/2011/0758http://www.zerodayinitiative.com/advisories/ZDI-11-110http://secunia.com/advisories/43860http://securityreason.com/securityalert/8164http://securitytracker.com/id?1025241http://www.securityfocus.com/archive/1/517119/100/0/threadedhttp://www.securityfocus.com/bid/46985http://www.vupen.com/english/advisories/2011/0758http://www.zerodayinitiative.com/advisories/ZDI-11-110
2011-03-25
Published