IBM Lotus Domino HTML Hidden Field Encrypted Password Disclosure
Medium Nessus Plugin ID 19309
SynopsisThe remote web server is affected by multiple information disclosure vulnerabilities.
DescriptionThe remote host is running a version of Lotus Domino Server that is prone to several information disclosure vulnerabilities. Specifically, users' password hashes and other data are included in hidden fields in the public address book 'names.nsf' readable by default by all users. Moreover, Domino does not use a 'salt' to compute password hashes, which makes it easier to crack passwords.
SolutionUpgrade to Lotus Domino Server version 6.0.6 / 6.5.5 or later.