CVE-2011-2893: IBM Lotus Symphony

Medium severity, CVSS 4.3. EPSS: 1.5% chance of exploitation in the next 30 days.

The DataPilot feature in IBM Lotus Symphony 3 before FP3 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .xls spreadsheet with an invalid Value reference.

Affected products

  • IBM Lotus Symphony: version 3.0.0 only; version 3.0.0.1 only; version 3.0.0.2 only

Published 2011-07-27. Last modified 2026-06-16.