CVE-2010-4546

IBM Lotus Notes Traveler < 8.5.1.2 - Authenticated Access Restriction Bypass via Attachment Download

Title source: llm
STIX 2.1

Description

IBM Lotus Notes Traveler before 8.5.1.2 does not reject an attachment download request for an e-mail message with a Prevent Copy attribute, which allows remote authenticated users to bypass intended access restrictions via this request.

Scores

EPSS 0.0118
EPSS Percentile 64.3%

Details

CWE
CWE-264
Status published
Products (8)
ibm/lotus_notes_traveler 8.0
ibm/lotus_notes_traveler 8.0.1
ibm/lotus_notes_traveler 8.0.1.2
ibm/lotus_notes_traveler 8.0.1.3
ibm/lotus_notes_traveler 8.5.0.0
ibm/lotus_notes_traveler 8.5.0.1
ibm/lotus_notes_traveler 8.5.0.2
ibm/lotus_notes_traveler < 8.5.1.1
Published Dec 16, 2010
Tracked Since Feb 18, 2026