5.5

CVE-2022-38654

HCL Domino is susceptible to an information disclosure vulnerability.  In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions.  An authenticated attacker could leverage this vulnerability to access attributes from a user's person record.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HcltechDomino Version9.0.1 Update-
HcltechDomino Version9.0.1 Updatefeature_pack_10_interim_fix_3
HcltechDomino Version9.0.1 Updatefeature_pack_10_interim_fix_4
HcltechDomino Version9.0.1 Updatefeature_pack_10_interim_fix_5
HcltechDomino Version9.0.1 Updatefeature_pack_8
HcltechDomino Version9.0.1 Updatefeature_pack_8_interim_fix_1
HcltechDomino Version9.0.1 Updatefeature_pack_8_interim_fix_2
HcltechDomino Version9.0.1 Updatefeature_pack_8_interim_fix_3
HcltechDomino Version9.0.1 Updatefixpack_3
HcltechDomino Version9.0.1 Updatefixpack_4
HcltechDomino Version9.0.1 Updatefixpack_5
HcltechDomino Version9.0.1 Updatefixpack_6
HcltechDomino Version9.0.1 Updatefixpack_7
HcltechDomino Version9.0.1 Updatefixpack_8
HcltechDomino Version9.0.1 Updatefixpack_9
HcltechDomino Version10.0.0
HcltechDomino Version10.0.1 Update-
HcltechDomino Version10.0.1 Updatefixpack_1
HcltechDomino Version10.0.1 Updatefixpack_2
HcltechDomino Version10.0.1 Updatefixpack_3
HcltechDomino Version10.0.1 Updatefixpack_4
HcltechDomino Version10.0.1 Updatefixpack_5
HcltechDomino Version10.0.1 Updatefixpack_6
HcltechDomino Version10.0.1 Updatefixpack_7
HcltechDomino Version11.0.1 Update-
HcltechDomino Version11.0.1 Updatefixpack_1
HcltechDomino Version11.0.1 Updatefixpack_2
HcltechDomino Version11.0.1 Updatefixpack_3
HcltechDomino Version11.0.1 Updatefixpack_4
HcltechDomino Version11.0.1 Updatefixpack_5
HcltechDomino Version12.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.231
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
psirt@hcl.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.