CVE-2012-5309

IBM Lotus Notes Traveler <8.5.3.3 - Auth Bypass

Title source: llm

Description

servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

Scores

EPSS 0.0055
EPSS Percentile 67.7%

Classification

CWE
CWE-287
Status draft

Affected Products (12)

ibm/lotus_notes_traveler
ibm/lotus_notes_traveler
ibm/lotus_notes_traveler
ibm/lotus_notes_traveler
ibm/lotus_notes_traveler
ibm/lotus_notes_traveler
ibm/lotus_notes_traveler
ibm/lotus_notes_traveler
ibm/lotus_notes_traveler
ibm/lotus_notes_traveler
ibm/lotus_notes_traveler
ibm/lotus_notes_traveler

Timeline

Published Oct 08, 2012
Tracked Since Feb 18, 2026