IBM Lotus Domino WebMail Information Disclosure Vulnerability

IBM Lotus Domino WebMail is affected by an information-disclosure vulnerability.

An attacker can obtain a user's password hash. and then carry out brute-force attacks to crack the password and gain access to the user's account.

Further reports indicate that an attacker can use Lotus Notes Client to view the address book and retrieve the password hashes.


 

Privacy Statement
Copyright 2010, SecurityFocus