
<p>IBM's Notes/Domino, an email and workgroup system that is especially popular in large companies, has a huge security problem that should be fixed soon with an update. Even just opening an email could launch the installation of spyware on a Notes user's computer.</p><p>Java embedded in web pages has, for some time now, been criticised as a security issue and automatic execution of JavaScript code when an email is opened can also have unwanted consequences, with information potentially being shared about when and where the email was read. That's why pretty much all email programs turn off both JavaScript and Java when displaying an HTML email except IBM's Notes.</p><p>After hearing from a third-party security expert, however, IBM has now also realised that designing Notes clients to load and execute JavaScript code and even Java applets from external servers without asking for any permission presents a security risk especially since Lotus Notes uses a Java environment that is already known for its highly critical security holes (IBM Java 6 SR12).</p><p>"Interim fixes" are now available that fix the problem by disabling these functions. Users can also manually change Notes settings to work around the issue, for example by setting the following variables in the notes.ini file:EnableJavaApplets=0EnableLiveConnect=0EnableJavaScript=0</p><p><a href="http://www.h-online.com/security/news/item/Huge-Java-hole-in-Lotus-Notes-1855406.html">Keep reading...</a></p>