CVE-2009-5034

IBM Lotus Notes Traveler < 8.5.0.2 - Authenticated Denial of Service via Large Data Sync

Title source: llm
STIX 2.1

Description

IBM Lotus Notes Traveler before 8.5.0.2 allows remote authenticated users to cause a denial of service (memory consumption and daemon crash) by syncing a large volume of data, related to the launch of a new process to handle the data while the previous process is still operating on the data.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64741
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1LO41707

Scores

EPSS 0.0114
EPSS Percentile 63.3%

Details

CWE
CWE-399
Status published
Products (6)
ibm/lotus_notes_traveler 8.0
ibm/lotus_notes_traveler 8.0.1
ibm/lotus_notes_traveler 8.0.1.2
ibm/lotus_notes_traveler 8.0.1.3
ibm/lotus_notes_traveler 8.5.0.0
ibm/lotus_notes_traveler < 8.5.0.1
Published Dec 16, 2010
Tracked Since Feb 18, 2026