CVE-2008-7253
IBM Lotus Domino Server - Cross-Site Tracing via HTTP TRACE Method
Title source: llmDescription
The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.
References (4)
Core 4
Core References
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?&uid=swg21201202
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/867593
Third Party Advisory, US Government Resource x_refsource_confirm
http://www.kb.cert.org/vuls/id/AAMN-5K42VN
Third Party Advisory, US Government Resource x_refsource_confirm
http://www.kb.cert.org/vuls/id/AAMN-5K42VT
Scores
EPSS
0.0209
EPSS Percentile
79.7%
Details
CWE
CWE-16
Status
published
Products (4)
ibm/lotus_domino_server
6.0
ibm/lotus_domino_server
6.5
ibm/lotus_domino_server
7.0
ibm/lotus_domino_server
8.0
Published
Jan 25, 2010
Tracked Since
Feb 18, 2026