Description
Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/1619
Vendor Advisory mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/9478
Scores
EPSS
0.0031
EPSS Percentile
23.0%
Details
Status
published
Products (1)
ibm/lotus_cc_mail
8.0
Published
Sep 08, 1997
Tracked Since
Feb 18, 2026