6.5

CVE-2020-4127

HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and 11.0.1 FP1 and later.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Hcl Domino Version < 9.0.1
Hcltech ≫ Hcl Domino Version >= 10.0.0 < 10.0.1
Hcltech ≫ Hcl Domino Version >= 11.0.0 < 11.0.1
Hcltech ≫ Hcl Domino Version 9.0.1 Update -
Hcltech ≫ Hcl Domino Version 9.0.1 Update feature_pack_10_interim_fix_2
Hcltech ≫ Hcl Domino Version 9.0.1 Update feature_pack_10_interim_fix_3
Hcltech ≫ Hcl Domino Version 9.0.1 Update feature_pack_10_interim_fix_4
Hcltech ≫ Hcl Domino Version 9.0.1 Update feature_pack_10_interim_fix_5
Hcltech ≫ Hcl Domino Version 10.0.1 Update -
Hcltech ≫ Hcl Domino Version 10.0.1 Update fixpack1
Hcltech ≫ Hcl Domino Version 10.0.1 Update fixpack2
Hcltech ≫ Hcl Domino Version 10.0.1 Update fixpack3
Hcltech ≫ Hcl Domino Version 10.0.1 Update fixpack4
Hcltech ≫ Hcl Domino Version 10.0.1 Update fixpack5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.371
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0085409
Vendor Advisory