CVE-2012-4846: IBM Lotus Notes

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, aka SPRs JMAS7TRNLN and SRAO8U3Q68.

Affected products

  • IBM Lotus Notes: version 8.5.0.0 only; version 8.5.0.1 only; version 8.5.1 only; version 8.5.1.0 only; version 8.5.1.1 only; version 8.5.1.2 only; …

Published 2012-12-19. Last modified 2026-06-16.