RULE(RULE ID:310473)

Rule General Information
Release Date: 2019-05-09
Rule Name: IBM iNotes ActiveX Control Integer Overflow Vulnerability -1 (CVE-2013-3027)
Severity:
CVE ID:
CNNVD ID:
Rule Protection Details
Description: Integer overflow in the DWA9W ActiveX control in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to execute arbitrary code via a crafted web page, aka SPR PTHN97XHFW.
Impact: An attacker can exploit the affected software with a integer overflow vulnerability. Successful exploit leads to execute arbitrary code, and failed exploit may disturb the software logic and cause denial of service.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: http://www-01.ibm.com/support/docview.wss?uid=swg21644599
http://www-01.ibm.com/support/docview.wss?uid=swg21645503
https://exchange.xforce.ibmcloud.com/vulnerabilities/84381
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www-01.ibm.com/support/docview.wss?uid=swg21645503