IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email message to another user, which allows user-assisted remote attackers to bypass Execution Control List (ECL) protection.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2008/0600/references | vdb entry |
http://secunia.com/advisories/29031 | third party advisory |
http://www-1.ibm.com/support/docview.wss?uid=swg21257250 |