peter bassill · operator
$ cve CVE-2011-1519 JSON

CVE-2011-1519 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 9.2% (pctl 95)

Patch early

A public exploit exists.

Description

The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS9.2% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2011-03-25
Last modified2026-06-16

Affected (1)

VendorProduct
ibmlotus domino

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD