CVE-2011-1519

IBM Lotus Domino <8.x - Auth Bypass

Title source: llm

Description

The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Alexey Sintsov · htmlremotejsp
https://www.exploit-db.com/exploits/18179

Scores

EPSS 0.0906
EPSS Percentile 92.5%

Classification

CWE
CWE-287
Status draft

Affected Products (33)

ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
... and 18 more

Timeline

Published Mar 25, 2011
Tracked Since Feb 18, 2026