CVE-2006-4763
IBM Lotus Domino Web Access (DWA) 7.0.1 - Privilege Escalation
Title source: llmDescription
IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client's Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows remote attackers to obtain a user's privileges by intercepting the LtpaToken cookie.
References (7)
Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28881
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/445821/100/0/threaded
Mailing List mailing-list
x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049408.html
Various Sources x_refsource_misc
http://www.fishnetsecurity.com/csirt/disclosure/ibm
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/19966
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/1571
Various Sources x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21245589
Scores
EPSS
0.0183
EPSS Percentile
76.6%
Details
Status
published
Products (1)
ibm/lotus_domino_web_access
7.0.1
Published
Sep 13, 2006
Tracked Since
Feb 18, 2026