CVE-2022-38654
Summary
| CVE | CVE-2022-38654 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-04 21:15:00 UTC |
| Updated | 2023-11-07 03:50:00 UTC |
| Description | HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a user's person record. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hcltech | Domino | 10.0.0 | All | All | All |
| Application | Hcltech | Domino | 10.0.1 | - | All | All |
| Application | Hcltech | Domino | 10.0.1 | fixpack_1 | All | All |
| Application | Hcltech | Domino | 10.0.1 | fixpack_2 | All | All |
| Application | Hcltech | Domino | 10.0.1 | fixpack_3 | All | All |
| Application | Hcltech | Domino | 10.0.1 | fixpack_4 | All | All |
| Application | Hcltech | Domino | 10.0.1 | fixpack_5 | All | All |
| Application | Hcltech | Domino | 10.0.1 | fixpack_6 | All | All |
| Application | Hcltech | Domino | 10.0.1 | fixpack_7 | All | All |
| Application | Hcltech | Domino | 11.0.1 | - | All | All |
| Application | Hcltech | Domino | 11.0.1 | fixpack_1 | All | All |
| Application | Hcltech | Domino | 11.0.1 | fixpack_2 | All | All |
| Application | Hcltech | Domino | 11.0.1 | fixpack_3 | All | All |
| Application | Hcltech | Domino | 11.0.1 | fixpack_4 | All | All |
| Application | Hcltech | Domino | 11.0.1 | fixpack_5 | All | All |
| Application | Hcltech | Domino | 12.0 | All | All | All |
| Application | Hcltech | Domino | 9.0.1 | - | All | All |
| Application | Hcltech | Domino | 9.0.1 | feature_pack_10_interim_fix_3 | All | All |
| Application | Hcltech | Domino | 9.0.1 | feature_pack_10_interim_fix_4 | All | All |
| Application | Hcltech | Domino | 9.0.1 | feature_pack_10_interim_fix_5 | All | All |
| Application | Hcltech | Domino | 9.0.1 | feature_pack_8 | All | All |
| Application | Hcltech | Domino | 9.0.1 | feature_pack_8_interim_fix_1 | All | All |
| Application | Hcltech | Domino | 9.0.1 | feature_pack_8_interim_fix_2 | All | All |
| Application | Hcltech | Domino | 9.0.1 | feature_pack_8_interim_fix_3 | All | All |
| Application | Hcltech | Domino | 9.0.1 | fixpack_3 | All | All |
| Application | Hcltech | Domino | 9.0.1 | fixpack_4 | All | All |
| Application | Hcltech | Domino | 9.0.1 | fixpack_5 | All | All |
| Application | Hcltech | Domino | 9.0.1 | fixpack_6 | All | All |
| Application | Hcltech | Domino | 9.0.1 | fixpack_7 | All | All |
| Application | Hcltech | Domino | 9.0.1 | fixpack_8 | All | All |
| Application | Hcltech | Domino | 9.0.1 | fixpack_9 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: HCL Domino is susceptible to an information disclosure vulnerability (CVE-2022-38654) - Customer Support | MISC | support.hcltechsw.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.