CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2016-6087 漏洞信息: IBM Domino TLS server's Diffie-Hellman parameter Vulnerability (swg22002808)

2017年6月13日 983点热度 0人点赞 0条评论

漏洞类别:Local

漏洞等级:

漏洞信息

IBM Domino (formerly IBM Lotus Domino) is an advanced platform for hosting social business applications.

IBM Domino is vulnerable to a information disclosure vulnerability which allows an attacker to steal credentials with the help of using multiple sessions and large amounts of data using Domino TLS Key Exchange validation.

Affected Versions
IBM Domino 9.0.1 through 9.0.1 FP7 IF2
IBM Domino 8.5.3 through 8.5.3 FP6 IF17
All 9.0.x, 9.0, 8.5.x releases of IBM Domino prior to those listed above

QID Detection Logic (authenticated):
The QID checks for the install path for IBM Domino via the registry key "HKLM\SOFTWARE\Lotus\Domino" on the value "Path". The QID flags if it finds a vulnerable version of of the file "<Install Path>nsd.exe" i.e. version prior to 9.0.18.0.

漏洞危害

Successful exploitation of the vulnerability will cause information disclosure.

解决方案

Refer to IBM advisory swg22002808 to obtain more information.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

swg22002808

0daybank

标签: 暂无
最后更新:2017年6月13日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me