Vulnerability Bulletins |
Vulnerabilidad crítica en Lotus Notes |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Obtener acceso |
| Dificulty | Avanzado |
| Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
| Property | Value |
| Affected manufacturer | Comercial Software |
| Affected software |
Lotus Notes 8.0.2 Lotus Notes 8.5 Lotus Notes 8.5.1 Lotus Notes 8.5.2 Lotus Notes 8.5.3 |
Description |
|
|
Una nueva vulnerabilidad ha sido reportada en IBM Lotus Notes. Esta vulnerabilidad permite la ejecución remota de código. Lotus Notes podría permitir a un atacante remoto poder ejecutar comandos shell arbritarios. Para aprovechar esta vulnerabilidad, el atacante remoto debe convencer a un usuario de Notes que se ejecuta en Windows para hacer clic en una URL maliciosa. A fecha de 15 de junio del 2012, IBM no ha recibido ningún informe sobre la explotación de esta vulnerabilidad. |
|
Solution |
|
| IBM Lotus Notes comunica que para arreglar esta vulnerabilidad aconseja actualizar a la versión 8.5.3 Fix Pack cuando está disponible. | |
Standar resources |
|
| Property | Value |
| CVE | CVE-2012-2174 |
| BID | |
Other resources |
|
|
Página de IBM http://www-01.ibm.com/support/docview.wss?uid=swg21598348 ISS X-Force Database http://xforce.iss.net/xforce/xfdb/75320 |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2012-06-20 |






