CVE-2018-1411: IBM Client Application Access

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138710.

Affected products

  • IBM Client Application Access: version 1.0.0.1 only; version 1.0.1 only; version 1.0.1.2 only
  • IBM Notes: version 8.5.1.5 only; version 8.5.2.4 only; version 8.5.3.6 only; version 9.0 only; version 9.0.1.9 only

Published 2018-02-19. Last modified 2026-06-17.