The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=100094373621813&w=2 | mailing list |
http://www.kb.cert.org/vuls/id/984555 | third party advisory us government resource |
http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/5552251934afaa9585256c0000737a7f?OpenDocument&Highlight=0%2CAWHN4A8QWM | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/10685 | vdb entry |