<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>lekkimworld.comvulnerability</title>
    <link>http://lekkimworld.com/tags/vulnerability/</link>
    <description>IBM Lotus Notes/Domino, Websphere, IBM Connections, mobile, web, JavaScript, Java...</description>
    <language>en</language>
    <copyright>Mikkel Flindt Heisterberg (mh [at] intravision [dot] dk</copyright>
    <pubDate>Sat, 19 May 2012 06:50:25 GMT</pubDate>
    <dc:creator>Mikkel Flindt Heisterberg (mh [at] intravision [dot] dk</dc:creator>
    <dc:date>2012-05-19T06:50:25Z</dc:date>
    <dc:language>en</dc:language>
    <dc:rights>Mikkel Flindt Heisterberg (mh [at] intravision [dot] dk</dc:rights>
    <image>
      <title>lekkimworld.comvulnerability</title>
      <url>http://lekkimworld.com/tags/vulnerability/</url>
    </image>
    <item>
      <title>Is the security of the Notes/Domino Java implementation questionable? (security vulnerability in the Notes/Domino Java API)</title>
      <link>http://lekkimworld.com/2006/12/07/is_the_security_of_the_notes_domino_java_implementation_questionable_security_vulnerability_in_the_notes_domino_java_api.html</link>
      <content:encoded>During some security research into the Notes/Domino Java API I stumbled upon what I cannot judge to be anything but a &lt;b&gt;major&lt;/b&gt; flaw in the Java implementation of Notes/Domino. The flaw allows me to circumvent the restricted/unrestricted operations security model for agents as well as all security measures put in place by the SecurityManager installed by IBM. The research was done on Notes/Domino 7.0.1 but I cannot see why it shouldn't be applicable to prior releases. I have been working with the IBM Security Response Team to assess the implications and &lt;a href="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21248025"&gt;technote #1248025&lt;/a&gt; (SPR# KLYH6NSJD2) has the official IBM response.&lt;p&gt;&lt;a href="http://lekkimworld.com/2006/12/07/is_the_security_of_the_notes_domino_java_implementation_questionable_security_vulnerability_in_the_notes_domino_java_api.html"&gt;Read more...&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <category domain="http://lekkimworld.com/categories/java/">Java</category>
      <category domain="http://lekkimworld.com/categories/ibm_products/">IBM</category>
      <category domain="http://lekkimworld.com/tags/domino/">domino</category>
      <category domain="http://lekkimworld.com/tags/java/">java</category>
      <category domain="http://lekkimworld.com/tags/security/">security</category>
      <category domain="http://lekkimworld.com/tags/vulnerability/">vulnerability</category>
      <pubDate>Thu, 07 Dec 2006 11:14:47 GMT</pubDate>
      <guid isPermaLink="false">tag:lekkimworld.com,2006-12-07:default/1165490087755</guid>
      <dc:date>2006-12-07T11:14:47Z</dc:date>
    </item>
    <item>
      <title>Security threats of syndicated content</title>
      <link>http://lekkimworld.com/2006/08/07/security_threats_of_syndicated_content.html</link>
      <content:encoded>I guess it had to happen or will happen at some point that RSS is used as the vector to exploit some kind of security vulnerability.&lt;p&gt;&lt;a href="http://lekkimworld.com/2006/08/07/security_threats_of_syndicated_content.html"&gt;Read more...&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <category domain="http://lekkimworld.com/tags/rss/">rss</category>
      <category domain="http://lekkimworld.com/tags/security/">security</category>
      <category domain="http://lekkimworld.com/tags/vulnerability/">vulnerability</category>
      <pubDate>Mon, 07 Aug 2006 09:01:02 GMT</pubDate>
      <guid isPermaLink="false">tag:lekkimworld.com,2006-08-07:default/1154941262001</guid>
      <dc:date>2006-08-07T09:01:02Z</dc:date>
    </item>
  </channel>
</rss>


