5.5

CVE-2022-38654

HCL Domino is susceptible to an information disclosure vulnerability

HCL Domino is susceptible to an information disclosure vulnerability.  In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions.  An authenticated attacker could leverage this vulnerability to access attributes from a user's person record.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Domino Version 9.0.1 Update -
Hcltech ≫ Domino Version 9.0.1 Update feature_pack_10_interim_fix_3
Hcltech ≫ Domino Version 9.0.1 Update feature_pack_10_interim_fix_4
Hcltech ≫ Domino Version 9.0.1 Update feature_pack_10_interim_fix_5
Hcltech ≫ Domino Version 9.0.1 Update feature_pack_8
Hcltech ≫ Domino Version 9.0.1 Update feature_pack_8_interim_fix_1
Hcltech ≫ Domino Version 9.0.1 Update feature_pack_8_interim_fix_2
Hcltech ≫ Domino Version 9.0.1 Update feature_pack_8_interim_fix_3
Hcltech ≫ Domino Version 9.0.1 Update fixpack_3
Hcltech ≫ Domino Version 9.0.1 Update fixpack_4
Hcltech ≫ Domino Version 9.0.1 Update fixpack_5
Hcltech ≫ Domino Version 9.0.1 Update fixpack_6
Hcltech ≫ Domino Version 9.0.1 Update fixpack_7
Hcltech ≫ Domino Version 9.0.1 Update fixpack_8
Hcltech ≫ Domino Version 9.0.1 Update fixpack_9
Hcltech ≫ Domino Version 10.0.0
Hcltech ≫ Domino Version 10.0.1 Update -
Hcltech ≫ Domino Version 10.0.1 Update fixpack_1
Hcltech ≫ Domino Version 10.0.1 Update fixpack_2
Hcltech ≫ Domino Version 10.0.1 Update fixpack_3
Hcltech ≫ Domino Version 10.0.1 Update fixpack_4
Hcltech ≫ Domino Version 10.0.1 Update fixpack_5
Hcltech ≫ Domino Version 10.0.1 Update fixpack_6
Hcltech ≫ Domino Version 10.0.1 Update fixpack_7
Hcltech ≫ Domino Version 11.0.1 Update -
Hcltech ≫ Domino Version 11.0.1 Update fixpack_1
Hcltech ≫ Domino Version 11.0.1 Update fixpack_2
Hcltech ≫ Domino Version 11.0.1 Update fixpack_3
Hcltech ≫ Domino Version 11.0.1 Update fixpack_4
Hcltech ≫ Domino Version 11.0.1 Update fixpack_5
Hcltech ≫ Domino Version 12.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.089
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
psirt@hcl.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0101017
Vendor Advisory