Normal Lotus SameTime login credential encryption with 1.5 and 3.0 Windows clients use RC2 to encrypt the password, and even sends the key along with the login packet allowing an attacker to decrypt the credentials and steal a user’s IM identity.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31520/lotus.txt
Source: https://packetstormsecurity.com/files/31520/lotus.txt.html

