Skip to main content
 
developerWorks
AIX and UNIX
Information Mgmt
Lotus
New to Lotus
Products
How to buy
Downloads
Live demos
Technical library
Training
Support
Forums & community
Events
Rational
Tivoli
WebSphere
Java™ technology
Linux
Open source
SOA and Web services
Web development
XML
My developerWorks
About dW
Submit content
Feedback



developerWorks  >  Lotus  >  Forums & community  >  Notes/Domino 4 and 5 Forum

Notes/Domino 4 and 5 Forum

developerWorks

  

Sign in to participate

Official Lotus Response to "Domino Server Directory Traversal Vulnerability"
Katherine Spanbauer 9.Jan.01 03:07 PM a Web browser
Domino Server -- HTTP 5.0.6 All Platforms

This document is intended to address the "Domino Server Directory Traversal Vulnerability" recently reported at http://www.securityfocus.com and can be used for discussing this issue with customers. This will be posted shortly to the Lotus Security Zone web site at http://www.lotus.com/security. Any updates to this document will be posted there, so please refer to that copy for the latest information.

What is the nature of the vulnerability?
Given a known path and file name, files may accessed from a Domino server running the HTTP task. This is limited to the file system (or drive) on which the Domino server is installed. It is not possible to browse the file system, but if a file name can be correctly guessed at, it can be accessed.

What versions of Domino are affected?
R5.0 - R5.0.6
R4x is not affected

How can I track this issue?
The SPR (Software Problem Report) number is KSPR4SPQ5S. When an SPR is fixed, it is posted in the Fix List database on Notes.net --> http://www.notes.net/R5FixList.nsf

What are Lotus' plans to address this issue?
Lotus is treating this with the highest priority and has a fix being tested now. This fix is planned for R5.0.6a and it will be posted to http://notes.net as soon as it is available.

Is there a workaround available?
Yes. Until R5.0.6a is available, the following workaround is recommended:

Open the Administration Client
Select the server you want to administer
"Configuration" tab / "Server" section / Current server document :
               Press the "Web" button
               Select "Create URL mapping/redirection"
In the URL redirection document
  + "Basics" tab
         Select: URL ---> Redirection URL
  + "Mapping" tab
         Incoming URL: *..*
         Redirection URL: [the URL you want to redirect to, for example "http://hostname/homepage.nsf"]
Save the document
Restart the HTTP task




Official Lotus Response to "Domino ... (Katherine Spanb... 9.Jan.01)
. . RE: Official Lotus Response to "Dom... (Aram Galestian 9.Jan.01)
. . RE: Update to recommended workaroun... (Katherine Spanb... 11.Jan.01)
. . RE: Official Lotus Response to "Dom... (Gary S White 15.Jan.01)
. . . . RE: Official Lotus Response to "Dom... (Jay Woo 16.Jan.01)
. . RE: Official Lotus Response to "Dom... (Paul Benwell 18.Jan.01)
. . . . RE: this seems to be implicit list ... (Normunds Kalnbe... 18.Jan.01)



Lotus Software


  Document options
Print this pagePrint this page

 Search this forum

  Forum views and search
Date (threaded)
Date (flat)
With excerpt
Author
Category
Platform
Release
Advanced search

 Sign In or Register
Sign in
Forgot your password?
Forgot your user name?
Create new registration

 RSS feedsRSS
All forum posts RSS
All main topics RSS
More Lotus RSS feeds

 Resources
Forum use and etiquette
Native Notes Access
Web site Feedback

  Lotus Support
Lotus Support
Product support pages index
Search knowledge base (Technotes)
Search support downloads
Lotus Support RSS

 Wikis
IBM accelerators
IBM Composite Applications
IBM Mashup Center
Lotus ActiveInsight
Lotus Connections
Lotus Domino
Lotus Domino Designer
Lotus Expeditor
Lotus Forms
Lotus Foundations
Lotus iNotes
Lotus Instructor Community Courseware
LotusLive
LotusLive iNotes
LotusLive Meetings & Events
Lotus Mobile Connect
Lotus Notes
Lotus Notes & Domino Application Development
Lotus Notes Traveler
Lotus Quickr
Lotus Sametime
Lotus Symphony
Lotus Web Content Management
Lotus Widget Factory
Lotus Workforce Management
WebSphere Dashboard Framework
WebSphere Portal
WebSphere Portal Express
WebSphere Portlet Factory

 Lotus Forums
Notes/Domino 8.5
Notes/Domino 8
Notes/Domino 6 and 7
Notes/Domino 4 and 5
Lotus ActiveInsight & WebSphere Dashboard Framework
Lotus Connections
Lotus Domino Document Manager
Lotus e-learning
Lotus Enterprise Integration
Lotus Expeditor
Lotus Forms
Lotus Labs
LotusLive Meetings
Lotus Mobile Connect
Lotus Quickr
Lotus Sametime
Lotus Sametime Unyte Events
Lotus Sametime Unyte Share
Lotus SmartSuite
Lotus Symphony
Lotus Symphony Developer Toolkit Support
Lotus Web Content Management
Lotus Widget Factory
Lotus Workflow
Lotus Workforce Management