5.9

CVE-2016-0270

IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a "forbidden attack." NOTE: this CVE has been incorrectly used for GCM nonce reuse issues in other products; see CVE-2016-10213 for the A10 issue, CVE-2016-10212 for the Radware issue, and CVE-2017-5933 for the Citrix issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Client Application Access Version 1.0.0.1
Ibm ≫ Domino Version 9.0.1.3
Ibm ≫ Domino Version 9.0.1.4
Ibm ≫ Domino Version 9.0.1.5
Ibm ≫ Notes Version 9.0.1.3
Ibm ≫ Notes Version 9.0.1.4
Ibm ≫ Notes Version 9.0.1.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.1% 0.861
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www-01.ibm.com/support/docview.wss?uid=swg21979604
Patch
Vendor Advisory
Mitigation
http://www-01.ibm.com/support/docview.wss?uid=swg21979669
Patch
Vendor Advisory
Mitigation
http://www-01.ibm.com/support/docview.wss?uid=swg21979673
Patch
Vendor Advisory
Mitigation
http://www.securityfocus.com/bid/96062
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1037795
https://github.com/nonce-disrespect/nonce-disrespect
Third Party Advisory
https://support.citrix.com/article/CTX220329