9.8

CVE-2022-44754

HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView.  This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44750.  This vulnerability applies to software previously licensed by IBM.

Data is provided by the National Vulnerability Database (NVD)
HcltechDomino Version9.0
HcltechDomino Version9.0.1
HcltechDomino Version9.0.1 Update-
HcltechDomino Version9.0.1 Updatefeature_pack_10_interim_fix_3
HcltechDomino Version9.0.1 Updatefeature_pack_10_interim_fix_4
HcltechDomino Version9.0.1 Updatefeature_pack_10_interim_fix_5
HcltechDomino Version9.0.1 Updatefeature_pack_8
HcltechDomino Version9.0.1 Updatefeature_pack_8_interim_fix_1
HcltechDomino Version9.0.1 Updatefeature_pack_8_interim_fix_2
HcltechDomino Version9.0.1 Updatefeature_pack_8_interim_fix_3
HcltechDomino Version9.0.1 Updatefixpack_10
HcltechDomino Version9.0.1 Updatefixpack_3
HcltechDomino Version9.0.1 Updatefixpack_4
HcltechDomino Version9.0.1 Updatefixpack_5
HcltechDomino Version9.0.1 Updatefixpack_6
HcltechDomino Version9.0.1 Updatefixpack_7
HcltechDomino Version9.0.1 Updatefixpack_8
HcltechDomino Version9.0.1 Updatefixpack_9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.54% 0.807
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
psirt@hcl.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.