7.5

CVE-2020-14230

HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the server. Versions previous to releases 9.0.1 FP10 IF6, 10.0.1 FP5 and 11.0.1 are affected.

Data is provided by the National Vulnerability Database (NVD)
HcltechDomino Version < 9.0.1
HcltechDomino Version >= 10.0.0 < 10.0.1
HcltechDomino Version >= 11.0.0 < 11.0.1
HcltechDomino Version9.0.1 Update-
HcltechDomino Version9.0.1 Updatefeature_pack_10_interim_fix_3
HcltechDomino Version9.0.1 Updatefeature_pack_10_interim_fix_4
HcltechDomino Version9.0.1 Updatefeature_pack_8
HcltechDomino Version9.0.1 Updatefeature_pack_8_interim_fix_1
HcltechDomino Version9.0.1 Updatefeature_pack_8_interim_fix_2
HcltechDomino Version9.0.1 Updatefeature_pack_8_interim_fix_3
HcltechDomino Version10.0.1 Update-
HcltechDomino Version10.0.1 Updatefix_pack_1
HcltechDomino Version10.0.1 Updatefix_pack_2
HcltechDomino Version10.0.1 Updatefix_pack_3
HcltechDomino Version10.0.1 Updatefix_pack_4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.39% 0.569
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.