CVE-2002-0037
IBM Lotus Domino Server 5.x, 4.6x, 4.5x - Unauthenticated Access Control Bypass via NSFDbReadObject API
Title source: llmDescription
Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes API call (NSFDbReadObject) that directly accesses the object.
References (4)
Core 4
Core References
Third Party Advisory vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/10095.php
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2001-09/0150.html
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2001-09/0147.html
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/657899
Scores
EPSS
0.0263
EPSS Percentile
84.0%
Details
Status
published
Products (3)
ibm/lotus_domino_server
4.5
ibm/lotus_domino_server
4.6
ibm/lotus_domino_server
5
Published
Apr 22, 2002
Tracked Since
Feb 18, 2026