CVE-2010-0275

IBM Lotus iNotes <229.241 - Info Disclosure

Title source: llm
STIX 2.1

Description

Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle script commands in the status-alerts URL, which has unspecified impact and attack vectors, aka SPR LSHR7TBM58.

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38026
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0077
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/55471
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37675
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27017776

Scores

EPSS 0.0154
EPSS Percentile 72.3%

Details

Status published
Products (19)
ibm/lotus_inotes 229.011
ibm/lotus_inotes 229.021
ibm/lotus_inotes 229.031
ibm/lotus_inotes 229.041
ibm/lotus_inotes 229.051
ibm/lotus_inotes 229.061
ibm/lotus_inotes 229.101
ibm/lotus_inotes 229.111
ibm/lotus_inotes 229.131
ibm/lotus_inotes 229.141
... and 9 more
Published Jan 09, 2010
Tracked Since Feb 18, 2026