CVE-2009-5035
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
16/12/2010
Last modified:
11/04/2025
Description
The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle multiple outgoing e-mail messages between sync operations, which might allow remote attackers to read communications intended for other recipients by examining appended messages.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:lotus_notes_traveler:*:*:*:*:*:*:*:* | 8.5.0.1 (including) | |
| cpe:2.3:a:ibm:lotus_notes_traveler:8.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:lotus_notes_traveler:8.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:lotus_notes_traveler:8.0.1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:lotus_notes_traveler:8.0.1.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:lotus_notes_traveler:8.5.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO47028
- http://www-10.lotus.com/ldd/dominowiki.nsf/page.xsp?documentId=A6604E906E0DF2DF8525778B005D4466&action=openDocument
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO47028
- http://www-10.lotus.com/ldd/dominowiki.nsf/page.xsp?documentId=A6604E906E0DF2DF8525778B005D4466&action=openDocument



