Incomplete blacklist vulnerability in the Certificate...
Low severity
Unreviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Apr 9, 2025
Description
Published by the National Vulnerability Database
Oct 29, 2007
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Apr 9, 2025
Incomplete blacklist vulnerability in the Certificate Authority (CA) in IBM Lotus Domino before 7.0.3 allows local users, or attackers with physical access, to obtain sensitive information (passwords) when an administrator enters a "ca activate" or "ca unlock" command with any uppercase character, which bypasses a blacklist designed to suppress password logging, resulting in cleartext password disclosure in the console log and Admin panel.
References