CVE-2010-4546
IBM Lotus Notes Traveler < 8.5.1.2 - Authenticated Access Restriction Bypass via Attachment Download
Title source: llmDescription
IBM Lotus Notes Traveler before 8.5.1.2 does not reject an attachment download request for an e-mail message with a Prevent Copy attribute, which allows remote authenticated users to bypass intended access restrictions via this request.
References (3)
Core 3
Core References
Various Sources x_refsource_confirm
http://www-10.lotus.com/ldd/dominowiki.nsf/page.xsp?documentId=A6604E906E0DF2DF8525778B005D4466&action=openDocument
Various Sources x_refsource_confirm
http://www-10.lotus.com/ldd/dominowiki.nsf/dx/Lotus_Notes_Traveler_851_FP3_Release_Notes
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1LO49840
Scores
EPSS
0.0118
EPSS Percentile
64.3%
Details
CWE
CWE-264
Status
published
Products (8)
ibm/lotus_notes_traveler
8.0
ibm/lotus_notes_traveler
8.0.1
ibm/lotus_notes_traveler
8.0.1.2
ibm/lotus_notes_traveler
8.0.1.3
ibm/lotus_notes_traveler
8.5.0.0
ibm/lotus_notes_traveler
8.5.0.1
ibm/lotus_notes_traveler
8.5.0.2
ibm/lotus_notes_traveler
< 8.5.1.1
Published
Dec 16, 2010
Tracked Since
Feb 18, 2026