Lotus Domino Server Multiple Information Disclosure Vulnerabilities
Low Nessus Network Monitor Plugin ID 3114
SynopsisThe remote host may give an attacker information useful for future attacks.
DescriptionThe remote host is running a version of Lotus Domino Server that is prone to several information disclosure vulnerabilities. Specifically, users' password hashes and other data are included in hidden fields in the public address book 'names.nsf' that is readable by default by all users. Moreover, Domino does not use a 'salt' to compute password hashes, which makes it easier to crack passwords.
SolutionUpgrade to version 6.5.5, 6.0.6 or higher.