CVE-2009-3114
Last modified
CVE-2009-3114 is a vulnerability of currently unknown severity. The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer's Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K.. EPSS estimates a 2.25% chance of exploitation in the next 30 days.
Description
The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer's Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Lotus Notes | 8.5 |
References
- http://secunia.com/advisories/36813Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21403834Vendor Advisory
- http://secunia.com/advisories/36813Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21403834Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-3114?
How severe is CVE-2009-3114?
How do I fix CVE-2009-3114?
Are you affected by CVE-2009-3114?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
