cbcvebase.
CVE-2011-1519
published 2011-03-25

CVE-2011-1519: The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by…

PriorityP262critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
9.20%
94.8th percentile
The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino
ibmlotus_domino

Detection & IOCsextracted from sources · hover to see the quote

cookieCOOKIEFILE
  • Monitor for authentication requests to the IBM Lotus Domino Server Controller remote console where the COOKIEFILE field contains a UNC share pathname (e.g., \\<remote_host>\<share>\<file>), indicating an attempt to redirect credential verification to an attacker-controlled file share.
  • Alert on outbound SMB/CIFS connections (ports 139/445) originating from the Domino Server Controller process during authentication events, as exploitation causes the server to reach out to an attacker-controlled UNC path for credential file retrieval.
  • Target IBM Lotus Domino versions 8.5.3 and 8.5.2 FP3 specifically when triaging exploitation attempts; these were confirmed vulnerable 0-day versions at time of disclosure.
  • ·The vulnerability affects both Domino 7.x and 8.x branches; detection and patching scope should cover both major version lines, not just 8.x.
  • ·This CVE may overlap with CVE-2011-0920; review both advisories to avoid duplicate or conflicting detection rules.
  • ·Exploitation was confirmed on Windows 7 and Windows 2008 hosts; Linux/Unix Domino deployments may behave differently regarding UNC path handling.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.