CVE-2020-4127
Summary
| CVE | CVE-2020-4127 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-30 22:15:00 UTC |
| Updated | 2020-12-04 18:14:00 UTC |
| Description | HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and 11.0.1 FP1 and later. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hcltech | Hcl Domino | All | All | All | All |
| Application | Hcltech | Hcl Domino | 10.0.1 | - | All | All |
| Application | Hcltech | Hcl Domino | 10.0.1 | fixpack1 | All | All |
| Application | Hcltech | Hcl Domino | 10.0.1 | fixpack2 | All | All |
| Application | Hcltech | Hcl Domino | 10.0.1 | fixpack3 | All | All |
| Application | Hcltech | Hcl Domino | 10.0.1 | fixpack4 | All | All |
| Application | Hcltech | Hcl Domino | 10.0.1 | fixpack5 | All | All |
| Application | Hcltech | Hcl Domino | 9.0.1 | - | All | All |
| Application | Hcltech | Hcl Domino | 9.0.1 | feature_pack_10_interim_fix_2 | All | All |
| Application | Hcltech | Hcl Domino | 9.0.1 | feature_pack_10_interim_fix_3 | All | All |
| Application | Hcltech | Hcl Domino | 9.0.1 | feature_pack_10_interim_fix_4 | All | All |
| Application | Hcltech | Hcl Domino | 9.0.1 | feature_pack_10_interim_fix_5 | All | All |
| Application | Hcltech | Hcl Domino | All | All | All | All |
| Application | Hcltech | Hcl Domino | 10.0.1 | - | All | All |
| Application | Hcltech | Hcl Domino | 10.0.1 | fixpack1 | All | All |
| Application | Hcltech | Hcl Domino | 10.0.1 | fixpack2 | All | All |
| Application | Hcltech | Hcl Domino | 10.0.1 | fixpack3 | All | All |
| Application | Hcltech | Hcl Domino | 10.0.1 | fixpack4 | All | All |
| Application | Hcltech | Hcl Domino | 10.0.1 | fixpack5 | All | All |
| Application | Hcltech | Hcl Domino | 9.0.1 | - | All | All |
| Application | Hcltech | Hcl Domino | 9.0.1 | feature_pack_10_interim_fix_2 | All | All |
| Application | Hcltech | Hcl Domino | 9.0.1 | feature_pack_10_interim_fix_3 | All | All |
| Application | Hcltech | Hcl Domino | 9.0.1 | feature_pack_10_interim_fix_4 | All | All |
| Application | Hcltech | Hcl Domino | 9.0.1 | feature_pack_10_interim_fix_5 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| %short_descr - Customer Support | MISC | support.hcltechsw.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.