CVE-2011-1520

IBM Lotus Domino - Unauthenticated Administrative Access via Server Console

Title source: llm
STIX 2.1

Description

The default configuration of the server console in IBM Lotus Domino does not require a password (aka Server_Console_Password), which allows physically proximate attackers to perform administrative changes or obtain sensitive information via a (1) Load, (2) Tell, or (3) Set Configuration command.

Scores

EPSS 0.0047
EPSS Percentile 37.5%

Details

CWE
CWE-287
Status published
Products (1)
ibm/lotus_domino
Published Mar 25, 2011
Tracked Since Feb 18, 2026