IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote attackers to bypass intended restrictions on Java code execution and X-Confirm-Reading-To functionality via a crafted message, aka SPRs JMOY95BLM6 and JMOY95BN49.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2013/Apr/262 | mailing list |
http://www.kb.cert.org/vuls/id/912420 | third party advisory us government resource |
https://exchange.xforce.ibmcloud.com/vulnerabilities/83775 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg21633819 | vendor advisory |