7.5

CVE-2020-14230

HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the server. Versions previous to releases 9.0.1 FP10 IF6, 10.0.1 FP5 and 11.0.1 are affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Domino Version < 9.0.1
Hcltech ≫ Domino Version >= 10.0.0 < 10.0.1
Hcltech ≫ Domino Version >= 11.0.0 < 11.0.1
Hcltech ≫ Domino Version 9.0.1 Update -
Hcltech ≫ Domino Version 9.0.1 Update feature_pack_10_interim_fix_3
Hcltech ≫ Domino Version 9.0.1 Update feature_pack_10_interim_fix_4
Hcltech ≫ Domino Version 9.0.1 Update feature_pack_8
Hcltech ≫ Domino Version 9.0.1 Update feature_pack_8_interim_fix_1
Hcltech ≫ Domino Version 9.0.1 Update feature_pack_8_interim_fix_2
Hcltech ≫ Domino Version 9.0.1 Update feature_pack_8_interim_fix_3
Hcltech ≫ Domino Version 10.0.1 Update -
Hcltech ≫ Domino Version 10.0.1 Update fix_pack_1
Hcltech ≫ Domino Version 10.0.1 Update fix_pack_2
Hcltech ≫ Domino Version 10.0.1 Update fix_pack_3
Hcltech ≫ Domino Version 10.0.1 Update fix_pack_4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.26% 0.672
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0085303
Patch
Vendor Advisory