CVE-2009-5032

IBM Lotus Notes Traveler < 8.5.0.2 - Unencrypted E-Mail Transmission

Title source: llm
STIX 2.1

Description

The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is used without uploading a Notes ID file, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64743
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1LO38116

Scores

EPSS 0.0107
EPSS Percentile 61.4%

Details

CWE
CWE-310
Status published
Products (6)
ibm/lotus_notes_traveler 8.0
ibm/lotus_notes_traveler 8.0.1
ibm/lotus_notes_traveler 8.0.1.2
ibm/lotus_notes_traveler 8.0.1.3
ibm/lotus_notes_traveler 8.5.0.0
ibm/lotus_notes_traveler < 8.5.0.1
Published Dec 16, 2010
Tracked Since Feb 18, 2026