CVE-2011-1519
IBM Lotus Domino <8.x - Auth Bypass
Title source: llmDescription
The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Alexey Sintsov · htmlremotejsp
https://www.exploit-db.com/exploits/18179
References (7)
Scores
EPSS
0.0906
EPSS Percentile
92.5%
Classification
CWE
CWE-287
Status
draft
Affected Products (33)
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
... and 18 more
Timeline
Published
Mar 25, 2011
Tracked Since
Feb 18, 2026