- http://secunia.com/advisories/27279/
Release Date: 2007-10-23
Critical: Highly critical
Impact: Exposure of sensitive information, System access
Where: From remote
Solution Status: Vendor Patch
Software: IBM Lotus Notes 6.x, IBM Lotus Notes 7.x …
Solution: Update to version 7.0.3 or 8.0.
NOTE: Version 8.0 does not fix the vulnerability in wp6sr.dll. http://www-306.ibm.com/software/lotus/supp…tral/index.html …
IBM Lotus Notes Lotus 1-2-3 vuln - patch available
- http://secunia.com/advisories/27835/
Release Date: 2007-11-27
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Software: IBM Lotus Notes 7.x, IBM Lotus Notes 8.x
…The vulnerability is reported in versions 7.0 and 8.0.
Solution: Lotes Notes 7.x/8.x: Contact IBM Support for patches.
Original Advisory: IBM: http://www-1.ibm.com/support/docview.wss?uid=swg21285600
IBM Lotus Notes Java vuln - workaround available
- http://secunia.com/advisories/29035/
Release Date: 2008-02-20
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Workaround
Software: IBM Lotus Notes 6.x, IBM Lotus Notes 7.x
…The vulnerability is reported in versions 6.5.6 and 7.0.
Solution: Version 7.0.2 reportedly includes the JVM fix. The vendor recommends disabling "Enable Java access from JavaScript"…
Original Advisory: http://www-1.ibm.com/support/docview.wss?uid=swg21257249
- http://secunia.com/advisories/30309/
Release Date: 2008-05-22
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Software: IBM Lotus Sametime 7.x, IBM Lotus Sametime 8.x
…Successful exploitation may allow execution of arbitrary code.
Solution: Update to version 8.0.1 or apply hotfix ICAE-7DPP83 for Lotus Sametime 7.5.1 Cumulative Fix 1 (CF1). Contact IBM support for the patch if Sametime 7.5.1 CF1 is not deployed or if unable to update to 8.0.1. http://preview.tinyurl.com/5s6mz9
Original Advisory:
IBM: http://www-1.ibm.com/support/docview.wss?uid=swg21303920
- http://isc.sans.org/diary.html?storyid=4460
Last Updated: 2008-05-26 23:54:12 UTC - "Take a look at port 1533*. That's quite an increase in targeted computers reporting via DShield over the past few days…"
IBM Lotus Notes Buffer Overflow in Processing Excel Attachments Lets Remote Users Execute Arbitrary Code
- http://securitytracker.com/alerts/2009/Aug/1022769.html
Date: Aug 25 2009
Version(s): 6.5, 7.0, 8.0, 8.5
Description: A vulnerability was reported in IBM Lotus Notes. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted Microsoft Excel file attachment that, when double-clicked and viewed by the target user, will trigger a buffer overflow in keyview and execute arbitrary code on the target system. The code will run with the privileges of the target user…
Solution: The vendor has issued a patch, available from IBM customer support…
Vendor URL: http://www-01.ibm.com/support/docview.wss?uid=swg21396492 …