CVE-2006-4763

IBM Lotus Domino Web Access (DWA) 7.0.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client's Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows remote attackers to obtain a user's privileges by intercepting the LtpaToken cookie.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28881
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/445821/100/0/threaded
Various Sources x_refsource_misc
http://www.fishnetsecurity.com/csirt/disclosure/ibm
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19966
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1571

Scores

EPSS 0.0183
EPSS Percentile 76.6%

Details

Status published
Products (1)
ibm/lotus_domino_web_access 7.0.1
Published Sep 13, 2006
Tracked Since Feb 18, 2026