CVE-2016-0304: IBM Domino

High severity, CVSS 8.1. EPSS: 2.5% chance of exploitation in the next 30 days.

The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, aka SPR KLYHA7MM3J. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0920.

Affected products

  • IBM Domino: version 8.5.3 only; version 8.5.3.1 only; version 8.5.3.2 only; version 8.5.3.3 only; version 8.5.3.4 only; version 8.5.3.5 only; …

Published 2016-06-29. Last modified 2026-06-17.