Vulnerability Details CVE-2007-4309
IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a different vulnerability than CVE-2005-2696.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.1%
CVSS Severity
CVSS v2 Score 3.5
Products affected by CVE-2007-4309
-
cpe:2.3:a:ibm:lotus_notes:5.0
-
cpe:2.3:a:ibm:lotus_notes:6.0
-
cpe:2.3:a:ibm:lotus_notes:7.0
-
cpe:2.3:a:ibm:lotus_notes:7.0.1
-
cpe:2.3:a:ibm:lotus_notes:7.0.2