IBM.Lotus.Expeditor.cai.URI.Handler.Command.Execution

description-logoDescription

This indicates an attempt to exploit an argument injection vulnerability in IBM Lotus Expeditor.
The vulnerability is due to improper handling of "cai:" URIs and passing the "-launcher" argument to the "rcplauncher.exe" utility.

affected-products-logoAffected Products

IBM Lotus Expeditor Client 6.1

Impact logoImpact

System Compromise

recomended-action-logoRecommended Actions

Refer to the IBM Technote (FAQ) 1303813:

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2020-09-10 16.921 Sig Added