Overview
The default configuration of the Lotus Domino web server discloses system characteristics to anonymous remote users.
Description
The default configuration of the Lotus Domino web server discloses system information in the HTTP headers it returns to a web browser. If these headers are intercepted and viewed by a user browsing an affected Domino server, the headers will reveal the release version, build date, and operating system of the web server. |
Impact
This vulnerability presents an information leak that allows an attacker to identify system characteristics. |
Solution
Apply a patch from your vendor Lotus has released a patch that addresses this vulnerability; for further information, please see the Systems Affected section of this document. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported to the Bugtraq mailing list on September 19, 2001.
This document was written by Jeffrey P. Lanza.
Other Information
CVE IDs: | CVE-2001-1018 |
Severity Metric: | 0.23 |
Date Public: | 2000-06-14 |
Date First Published: | 2001-09-20 |
Date Last Updated: | 2002-01-10 23:48 UTC |
Document Revision: | 7 |