CVE-2008-7253

IBM Lotus Domino Server - Cross-Site Tracing via HTTP TRACE Method

Title source: llm
STIX 2.1

Description

The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.

References (4)

Core 4
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/867593
Third Party Advisory, US Government Resource x_refsource_confirm
http://www.kb.cert.org/vuls/id/AAMN-5K42VN
Third Party Advisory, US Government Resource x_refsource_confirm
http://www.kb.cert.org/vuls/id/AAMN-5K42VT

Scores

EPSS 0.0209
EPSS Percentile 79.7%

Details

CWE
CWE-16
Status published
Products (4)
ibm/lotus_domino_server 6.0
ibm/lotus_domino_server 6.5
ibm/lotus_domino_server 7.0
ibm/lotus_domino_server 8.0
Published Jan 25, 2010
Tracked Since Feb 18, 2026