// For flags

CVE-2011-1519

IBM Lotus Domino Server Controller - Authentication Bypass

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.

La consola remota en el controlador del servidor de IBM Lotus Domino v7.x y v8.x comprueba las credenciales contra un archivo ubicado en una ruta de acceso compartido UNC especificada por el cliente, lo que permite a atacantes remotos evitar la autenticación, y por lo tanto ejecutar código arbitrario, mediante la colocación de esta ruta en el campo COOKIEFILE. NOTA: esto puede superponerse al CVE-2011-0.920.

IBM Lotus Domino versions 8.5.3 and 8.5.2 FP3 suffer from an authentication bypass vulnerability.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-03-25 CVE Reserved
  • 2011-03-25 CVE Published
  • 2011-11-30 First Exploit
  • 2023-04-13 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
7.0
Search vendor "Ibm" for product "Lotus Domino" and version "7.0"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
7.0.1
Search vendor "Ibm" for product "Lotus Domino" and version "7.0.1"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
7.0.1.1
Search vendor "Ibm" for product "Lotus Domino" and version "7.0.1.1"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
7.0.2
Search vendor "Ibm" for product "Lotus Domino" and version "7.0.2"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
7.0.2.1
Search vendor "Ibm" for product "Lotus Domino" and version "7.0.2.1"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
7.0.2.2
Search vendor "Ibm" for product "Lotus Domino" and version "7.0.2.2"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
7.0.2.3
Search vendor "Ibm" for product "Lotus Domino" and version "7.0.2.3"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
7.0.3
Search vendor "Ibm" for product "Lotus Domino" and version "7.0.3"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
7.0.3.1
Search vendor "Ibm" for product "Lotus Domino" and version "7.0.3.1"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
7.0.4
Search vendor "Ibm" for product "Lotus Domino" and version "7.0.4"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
7.0.4.1
Search vendor "Ibm" for product "Lotus Domino" and version "7.0.4.1"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
7.0.4.2
Search vendor "Ibm" for product "Lotus Domino" and version "7.0.4.2"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.0
Search vendor "Ibm" for product "Lotus Domino" and version "8.0"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.0.1
Search vendor "Ibm" for product "Lotus Domino" and version "8.0.1"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.0.2
Search vendor "Ibm" for product "Lotus Domino" and version "8.0.2"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.0.2.1
Search vendor "Ibm" for product "Lotus Domino" and version "8.0.2.1"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.0.2.2
Search vendor "Ibm" for product "Lotus Domino" and version "8.0.2.2"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.0.2.3
Search vendor "Ibm" for product "Lotus Domino" and version "8.0.2.3"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.0.2.4
Search vendor "Ibm" for product "Lotus Domino" and version "8.0.2.4"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.0.2.5
Search vendor "Ibm" for product "Lotus Domino" and version "8.0.2.5"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.0.2.6
Search vendor "Ibm" for product "Lotus Domino" and version "8.0.2.6"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.5.0
Search vendor "Ibm" for product "Lotus Domino" and version "8.5.0"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.5.0.1
Search vendor "Ibm" for product "Lotus Domino" and version "8.5.0.1"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.5.1
Search vendor "Ibm" for product "Lotus Domino" and version "8.5.1"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.5.1.1
Search vendor "Ibm" for product "Lotus Domino" and version "8.5.1.1"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.5.1.2
Search vendor "Ibm" for product "Lotus Domino" and version "8.5.1.2"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.5.1.3
Search vendor "Ibm" for product "Lotus Domino" and version "8.5.1.3"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.5.1.4
Search vendor "Ibm" for product "Lotus Domino" and version "8.5.1.4"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.5.1.5
Search vendor "Ibm" for product "Lotus Domino" and version "8.5.1.5"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.5.2
Search vendor "Ibm" for product "Lotus Domino" and version "8.5.2"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.5.2.1
Search vendor "Ibm" for product "Lotus Domino" and version "8.5.2.1"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.5.2.2
Search vendor "Ibm" for product "Lotus Domino" and version "8.5.2.2"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Domino
Search vendor "Ibm" for product "Lotus Domino"
8.5.3
Search vendor "Ibm" for product "Lotus Domino" and version "8.5.3"
-
Affected