Affected Systems:
IBM Lotus Domino 7.0
Unaffected system:
IBM Lotus Domino 7.0.2 FP2
Describe:
The Lotus domino/notes server is a web-based application architecture that runs under the platform of Linux/unix and Microsoft Windows operating systems.
There is a vulnerability in Lotus Domino's proxy signature verification where a local attacker could exploit this vulnerability to elevate his or her privileges in the application.
If a remote attacker has designer or manager access to a database on a Domino server, and the design of the database is replaced with a template, the dispatch agent in the template is set to Enabled and signed by a trusted valid ID. The use of a modified agent allows some markup to be reused, resulting in the use of a signature that was previously validated rather than an invalid signature on the current proxy. Remote attackers can obtain full access administrator permissions in this way.
Vendor Patch:
Ibm
At present, the manufacturer has released the upgrade patch to fix this security issue, please go to the manufacturer's homepage to download:
http://www.ers.ibm.com/