|
Family: Web Servers --> Category: infos
Lotus Domino Server Information Disclosure Vulnerabilities Vulnerability Scan
Vulnerability Scan Summary Checks for information disclosure vulnerabilities in Lotus Domino Server
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server is affected by multiple information disclosure
vulnerabilities.
Description :
The remote host is running a version of Lotus Domino Server that is
prone to several information disclosure vulnerabilities.
Specifically, users' password hashes and other data are included in
hidden fields in the public address book 'names.nsf' readable by
default by all users. Moreover, Domino does not use a 'salt' to
compute password hashes, which makes it easier to crack passwords.
See also :
http://www.cybsec.com/vuln/default_configuration_information_disclosure_lotus_domino.pdf
Solution :
Upgrade to Lotus Domino Server version 6.0.6 / 6.5.5 or later.
Threat Level:
Low / CVSS Base Score : 2
(AV:R/AC:L/Au:NR/C:P/A:N/I:N/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|