CVE-2004-1621

UnknownEPSS 3.08%

Last modified

CVE-2004-1621 is a vulnerability of currently unknown severity. NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. EPSS estimates a 3.08% chance of exploitation in the next 30 days.

Description

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature

Metrics

EPSS Probability
3.08%

86.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
IbmLotus Domino6.0
IbmLotus Domino6.0.1
IbmLotus Domino6.0.2
IbmLotus Domino6.0.2_cf2
IbmLotus Domino6.0.3
IbmLotus Domino6.5.0
IbmLotus Domino6.5.1
IbmLotus Domino6.5.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2004-1621?
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature
How severe is CVE-2004-1621?
Severity scoring for CVE-2004-1621 is pending analysis. The EPSS model estimates a 3.08% probability of exploitation in the next 30 days.
How do I fix CVE-2004-1621?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2004-1621?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST