IBM Lotus Domino allows change of quota

lotus-quota-change (16575) The risk level is classified as MediumMedium Risk

Description:

Lotus Domino could allow a remote attacker to change their quota to any desired value. If the mailfile is imap-enabled, a remote attacker could make a Telnet connection to the imap-server and use the setquota command to change the quota to any desired value.


Consequences:

Data Manipulation

Remedy:

No remedy available as of July 9, 2011.

References:

Platforms Affected:

  • IBM Lotus Domino 6.5.0
  • IBM Lotus Domino 6.5.1

Reported:

Jun 30, 2004

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page