CVE Vulnerabilities

CVE-2021-27760

Published: May 06, 2022 | Modified: Jul 29, 2022
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.

Affected Software

Name Vendor Start Version End Version
Hcl_inotes Hcltech 11.0.0 (including) 11.0.0 (including)
Hcl_inotes Hcltech 11.0.1 (including) 11.0.1 (including)
Hcl_inotes Hcltech 11.0.1-fixpack1 (including) 11.0.1-fixpack1 (including)
Hcl_inotes Hcltech 11.0.1-fixpack2 (including) 11.0.1-fixpack2 (including)
Hcl_inotes Hcltech 11.0.1-fixpack3 (including) 11.0.1-fixpack3 (including)
Hcl_inotes Hcltech 11.0.1-fixpack4 (including) 11.0.1-fixpack4 (including)

References