CVE Vulnerabilities

CVE-2022-38654

Published: Nov 04, 2022 | Modified: Nov 07, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a users person record.

Affected Software

Name Vendor Start Version End Version
Domino Hcltech 9.0.1 (including) 9.0.1 (including)
Domino Hcltech 9.0.1-feature_pack_10_interim_fix_3 (including) 9.0.1-feature_pack_10_interim_fix_3 (including)
Domino Hcltech 9.0.1-feature_pack_10_interim_fix_4 (including) 9.0.1-feature_pack_10_interim_fix_4 (including)
Domino Hcltech 9.0.1-feature_pack_10_interim_fix_5 (including) 9.0.1-feature_pack_10_interim_fix_5 (including)
Domino Hcltech 9.0.1-feature_pack_8 (including) 9.0.1-feature_pack_8 (including)
Domino Hcltech 9.0.1-feature_pack_8_interim_fix_1 (including) 9.0.1-feature_pack_8_interim_fix_1 (including)
Domino Hcltech 9.0.1-feature_pack_8_interim_fix_2 (including) 9.0.1-feature_pack_8_interim_fix_2 (including)
Domino Hcltech 9.0.1-feature_pack_8_interim_fix_3 (including) 9.0.1-feature_pack_8_interim_fix_3 (including)
Domino Hcltech 9.0.1-fixpack_3 (including) 9.0.1-fixpack_3 (including)
Domino Hcltech 9.0.1-fixpack_4 (including) 9.0.1-fixpack_4 (including)
Domino Hcltech 9.0.1-fixpack_5 (including) 9.0.1-fixpack_5 (including)
Domino Hcltech 9.0.1-fixpack_6 (including) 9.0.1-fixpack_6 (including)
Domino Hcltech 9.0.1-fixpack_7 (including) 9.0.1-fixpack_7 (including)
Domino Hcltech 9.0.1-fixpack_8 (including) 9.0.1-fixpack_8 (including)
Domino Hcltech 9.0.1-fixpack_9 (including) 9.0.1-fixpack_9 (including)
Domino Hcltech 10.0.0 (including) 10.0.0 (including)
Domino Hcltech 10.0.1 (including) 10.0.1 (including)
Domino Hcltech 10.0.1-fixpack_1 (including) 10.0.1-fixpack_1 (including)
Domino Hcltech 10.0.1-fixpack_2 (including) 10.0.1-fixpack_2 (including)
Domino Hcltech 10.0.1-fixpack_3 (including) 10.0.1-fixpack_3 (including)
Domino Hcltech 10.0.1-fixpack_4 (including) 10.0.1-fixpack_4 (including)
Domino Hcltech 10.0.1-fixpack_5 (including) 10.0.1-fixpack_5 (including)
Domino Hcltech 10.0.1-fixpack_6 (including) 10.0.1-fixpack_6 (including)
Domino Hcltech 10.0.1-fixpack_7 (including) 10.0.1-fixpack_7 (including)
Domino Hcltech 11.0.1 (including) 11.0.1 (including)
Domino Hcltech 11.0.1-fixpack_1 (including) 11.0.1-fixpack_1 (including)
Domino Hcltech 11.0.1-fixpack_2 (including) 11.0.1-fixpack_2 (including)
Domino Hcltech 11.0.1-fixpack_3 (including) 11.0.1-fixpack_3 (including)
Domino Hcltech 11.0.1-fixpack_4 (including) 11.0.1-fixpack_4 (including)
Domino Hcltech 11.0.1-fixpack_5 (including) 11.0.1-fixpack_5 (including)
Domino Hcltech 12.0 (including) 12.0 (including)

References