Lucene search

K
cvelistHCLCVELIST:CVE-2022-38654
HistoryNov 04, 2022 - 8:19 p.m.

CVE-2022-38654 HCL Domino is susceptible to an information disclosure vulnerability

2022-11-0420:19:37
CWE-200
HCL
www.cve.org
hcl domino
information disclosure
vulnerability
xacl read restrictions
user's person record

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.6%

HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a user’s person record.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "HCL Domino",
    "vendor": "HCL Software",
    "versions": [
      {
        "status": "affected",
        "version": "9, 10, 11, 12"
      }
    ]
  }
]

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.6%

Related for CVELIST:CVE-2022-38654