Description:
Multiple vulnerabilities are found in IBM Lotus Notes System Debugger (NSD). A local attacker could use special crafted commands to exploit the vulnerabilities.
Affected Systems:
- IBM Notes 9.0.1 to IBM Notes 9.0.1 Fix Pack 10
- IBM Notes 9.0 to IBM Notes 9.0 Interim Fix 4
- IBM Notes 8.5.3 to IBM Notes 8.5.3 Fix Pack 6 Interim Fix 15
- IBM Notes 8.5.2 to IBM Notes 8.5.2 Fix Pack 4 Interim Fix 3
- IBM Notes 8.5.1 to IBM Notes 8.5.1 Fix Pack 5 Interim Fix 3
- IBM Notes 8.5 release
Impact:
Successful exploitation of the vulnerabilities could lead to privilege escalation and arbitrary commands execution.
Recommendation:
The vendor has released fixes to address the issues and they can be downloaded at the following URLs:
- IBM Notes Standard 9.0.1 Fix Pack 10 Interim Fix 1
http://www.ibm.com/support/fixcentral/quickorder?product=ibm%2FLotus%2FLotus+Notes&fixids=Notes_901FP10IF1_W32_Standard&source=SAR
- IBM Notes Basic 9.0.1 Fix Pack 10 Interim Fix 1
http://www.ibm.com/support/fixcentral/quickorder?product=ibm%2FLotus%2FLotus+Notes&fixids=Notes_901FP10IF1_W32_Basic&source=SAR
More Information:
http://www-01.ibm.com/support/docview.wss?uid=swg22010767
http://www-01.ibm.com/support/docview.wss?uid=swg22010777
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1714
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1720