CVE-2016-0304: IBM Domino
High severity, CVSS 8.1. EPSS: 2.5% chance of exploitation in the next 30 days.
The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, aka SPR KLYHA7MM3J. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0920.
Affected products
- IBM Domino: version 8.5.3 only; version 8.5.3.1 only; version 8.5.3.2 only; version 8.5.3.3 only; version 8.5.3.4 only; version 8.5.3.5 only; …
Published 2016-06-29. Last modified 2026-06-17.