Lucene search

K
cveHCLCVE-2020-4126
HistoryDec 01, 2020 - 12:15 a.m.

CVE-2020-4126

2020-12-0100:15:11
CWE-311
HCL
web.nvd.nist.gov
43
hcl
inotes
cve-2020-4126
vulnerability
security
cookie exposure
nvd
fix
hcl domino

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

62.4%

HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later.

Affected configurations

Nvd
Node
hcltechhcl_inotesRange9.010.0.1
OR
hcltechhcl_inotesRange11.0.011.0.1
OR
hcltechhcl_inotesMatch10.0.1-
OR
hcltechhcl_inotesMatch10.0.1fixpack1
OR
hcltechhcl_inotesMatch10.0.1fixpack2
OR
hcltechhcl_inotesMatch10.0.1fixpack3
OR
hcltechhcl_inotesMatch10.0.1fixpack4
OR
hcltechhcl_inotesMatch10.0.1fixpack5
OR
hcltechhcl_inotesMatch11.0.1-
OR
hcltechhcl_inotesMatch11.0.1fixpack1
VendorProductVersionCPE
hcltechhcl_inotes*cpe:2.3:a:hcltech:hcl_inotes:*:*:*:*:*:*:*:*
hcltechhcl_inotes10.0.1cpe:2.3:a:hcltech:hcl_inotes:10.0.1:-:*:*:*:*:*:*
hcltechhcl_inotes10.0.1cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack1:*:*:*:*:*:*
hcltechhcl_inotes10.0.1cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack2:*:*:*:*:*:*
hcltechhcl_inotes10.0.1cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack3:*:*:*:*:*:*
hcltechhcl_inotes10.0.1cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack4:*:*:*:*:*:*
hcltechhcl_inotes10.0.1cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack5:*:*:*:*:*:*
hcltechhcl_inotes11.0.1cpe:2.3:a:hcltech:hcl_inotes:11.0.1:-:*:*:*:*:*:*
hcltechhcl_inotes11.0.1cpe:2.3:a:hcltech:hcl_inotes:11.0.1:fixpack1:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "HCL iNotes",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "v10.0.1 FP6, v11.0.1 FP2 and later"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

62.4%

Related for CVE-2020-4126