Vulnerability Database

290,206

Total vulnerabilities in the database

CVE-2016-0304

The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, aka SPR KLYHA7MM3J. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0920.

  • Published: Jun 29, 2016
  • Updated: Apr 13, 2023
  • CVE: CVE-2016-0304
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.1
  • AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P
Software From Fixed in
ibm / domino 8.5.3.6 8.5.3.6.x
ibm / domino 8.5.3.5 8.5.3.5.x
ibm / domino 8.5.3.1 8.5.3.1.x
ibm / domino 8.5.3.4 8.5.3.4.x
ibm / domino 8.5.3 8.5.3.x
ibm / domino 8.5.3.2 8.5.3.2.x
ibm / domino 8.5.3.3 8.5.3.3.x
ibm / domino 8.5.2.4 8.5.2.4.x
ibm / domino 8.5.2.2 8.5.2.2.x
ibm / domino 8.5.2.3 8.5.2.3.x
ibm / domino 8.5.2.1 8.5.2.1.x
ibm / domino 8.5.2 8.5.2.x
ibm / domino 8.5.1.4 8.5.1.4.x
ibm / domino 8.5.1.1 8.5.1.1.x
ibm / domino 8.5.1.2 8.5.1.2.x
ibm / domino 8.5.1 8.5.1.x
ibm / domino 8.5.1.3 8.5.1.3.x
ibm / domino 8.5.1.5 8.5.1.5.x
ibm / domino 8.5.0 8.5.0.x
ibm / domino 9.0.1.1 9.0.1.1.x
ibm / domino 9.0.1.2 9.0.1.2.x
ibm / domino 9.0.1 9.0.1.x
ibm / domino 9.0.1.5 9.0.1.5.x
ibm / domino 9.0.1.4 9.0.1.4.x
ibm / domino 9.0.1.3 9.0.1.3.x