Junglewise Threat Intelligence

CVE-1999-1275: Lotus cc:Mail plaintext password storage in hidden file

CVE-1999-1275 · Severity: medium · CVSS 4.6 · Published 1997-09-08

Vendors: IBM.

Executive brief

Lotus cc:Mail, an enterprise email system, contains a security flaw where it stores the administrative postoffice password in plain text within a hidden file. Because this file has weak access controls, any user with local access to the system can read the password. This allows an unauthorized individual to gain administrative control over the email system, potentially leading to the exposure of sensitive communications or disruption of service.

Technical details

Lotus cc:Mail Release 8 suffers from an insecure storage of sensitive information vulnerability. The application stores the postoffice password in plaintext within a hidden configuration file. This file is created with insecure file system permissions, failing to restrict read access to authorized administrators only. A local attacker with standard user access can locate and read this file to obtain the administrative password. This leads to a full compromise of the cc:Mail postoffice, allowing the attacker to escalate privileges within the mail system.

Affected products

  • Lotus cc:Mail Release 8

Timeline

  • 1997-09-08: disclosed: Initial NVD publication date

References