4

CVE-2009-5033

IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, which allows remote authenticated users to obtain access to other users' data via a sync operation, related to storage of the data of multiple users within the same thread.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmLotus Notes Traveler Version <= 8.5.0.1
IbmLotus Notes Traveler Version8.0
IbmLotus Notes Traveler Version8.0.1
IbmLotus Notes Traveler Version8.0.1.2
IbmLotus Notes Traveler Version8.0.1.3
IbmLotus Notes Traveler Version8.5.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.393
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.